The most restrictive access , in this case exclusive access to www/admin with a resolution of 0750 , is always the most secure . Please note that in the permission mask above, users who are neither www nor admin members are not allowed to access the contents of the directory at all; this means reducing the likelihood that an unauthorized party registered in the system will gain access to potentially confidential information uploaded by users.
Remember that on most * nix platforms you also have a third, extremely flexible option , i.e. setting an ACL using setfacl . An ACL is a superset of what can be achieved using regular resolution bits and ownership methods. ACLs are an option when confronted with complex security settings (including permissions for each user, default owners, etc.), but you may need to first add acl to /etc/fstab in the mount options of the volume on which your directory is located, see man mount .) You can use the ACL if two or more users need access to the directory in question without being members of, say, the admin group.
vladr
source share