# Force Directory and File Permissions

**URL:** <https://help.nextcloud.com/t/force-directory-and-file-permissions/30540>\
**Category:** ℹ️ Support\
**Created:** [April 18, 2018, 3:26pm UTC](https://help.nextcloud.com/t/force-directory-and-file-permissions/30540 "2018-04-18T15:26:09Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![tlaughlin](https://help.nextcloud.com/user_avatar/help.nextcloud.com/tlaughlin/32/8807_2.png) [@tlaughlin](https://help.nextcloud.com/u/tlaughlin)\
**Post date:** [April 18, 2018, 3:26pm UTC](https://help.nextcloud.com/t/force-directory-and-file-permissions/30540/1 "2018-04-18T15:26:09Z")

</div>

When a user creates a folder or uploads a file using nextcloud, how do I force file ownership and group permissions for the file. Currently they are getting created as www-data:www-data and I’d like them to be created with a certain group always (“Domain Users”)

Thank You!

TL

---

<div class="post-metadata">

**Author:** ![Schmu](https://help.nextcloud.com/user_avatar/help.nextcloud.com/schmu/32/7823_2.png) [@Schmu](https://help.nextcloud.com/u/Schmu)\
**Post date:** [April 20, 2018, 7:02am UTC](https://help.nextcloud.com/t/force-directory-and-file-permissions/30540/2 "2018-04-20T07:02:57Z")

</div>

Hi,

My guess is: run the web server with that group.

---

<div class="post-metadata">

**Author:** ![MichaIng](https://help.nextcloud.com/user_avatar/help.nextcloud.com/michaing/32/2125_2.png) [@MichaIng](https://help.nextcloud.com/u/MichaIng)\
**Post date:** [April 21, 2018, 12:34am UTC](https://help.nextcloud.com/t/force-directory-and-file-permissions/30540/3 "2018-04-21T00:34:29Z")

</div>

Hmm, not sure if I understood right, but you don’t mean Nextcloud internal user groups right?

Nextcloud cannot influence with what “system” user and group files are created. They are created by the webserver according to its user and group settings within e.g. /etc/apache2/apache.conf

I don’t know about any method to differentiate this for e.g. different Nextcloud users. This also makes sense as the webserver has just it’s single defined user permissions that it uses to create files.

So yes you can adjust the webserver user and group and with this the files it creates, but only for the whole Nextcloud instance at once and all other web sites it provides.

---

<div class="post-metadata">

**Author:** ![budy](https://help.nextcloud.com/user_avatar/help.nextcloud.com/budy/32/697_2.png) [@budy](https://help.nextcloud.com/u/budy)\
**Post date:** [April 21, 2018, 7:55am UTC](https://help.nextcloud.com/t/force-directory-and-file-permissions/30540/4 "2018-04-21T07:55:51Z")

</div>

> [@tlaughlin](#):
>
> I’d like them to be created with a certain group always (“Domain Users”)

Could it be, that you want to share that data via file services as well? This is the only reason, your request makes sense. If that is the case - don’t do it - at least not for the actual NC data folder. You will screw up the relation between your stored data and their states in the DB, unless you’re jumping through some hoops and establish some kind of periodical sync for that.

NC is not a file server and it shouldn’t be treated as one. If you want to sync using NC and have the same data shared via SMB, use the external storage app to make that data available to NC, but not the other way round.

---

<div class="post-metadata">

**Author:** ![tlaughlin](https://help.nextcloud.com/user_avatar/help.nextcloud.com/tlaughlin/32/8807_2.png) [@tlaughlin](https://help.nextcloud.com/u/tlaughlin)\
**Post date:** [April 23, 2018, 4:47pm UTC](https://help.nextcloud.com/t/force-directory-and-file-permissions/30540/5 "2018-04-23T16:47:10Z")

</div>

So I have a SMB share that has been a file share for many years. We have installed a nextcloud instance and added the SMB share as an external storage location in nextcloud.

Some of our users have begin using nextcloud to create folders within the SMB share but they are added with the webserver user and group. Makes since that I could change the webserver group to one that has shared permissions but is there a way to force the chmod permission when a file or folder is created through nextcloud?

Thanks

---

<div class="post-metadata">

**Author:** ![Tom\_B](https://help.nextcloud.com/user_avatar/help.nextcloud.com/tom_b/32/3101_2.png) [@Tom\_B](https://help.nextcloud.com/u/Tom_B)\
**Post date:** [April 23, 2018, 5:04pm UTC](https://help.nextcloud.com/t/force-directory-and-file-permissions/30540/6 "2018-04-23T17:04:34Z")

</div>

These files will be stored with the user and group of the user that nextcloud uses to access the share.

You could run a cron script to **chgrp** them to the group you want. It’s as simplistic solution but maybe it’s all you need?

---

<div class="post-metadata">

**Author:** ![Schmu](https://help.nextcloud.com/user_avatar/help.nextcloud.com/schmu/32/7823_2.png) [@Schmu](https://help.nextcloud.com/u/Schmu)\
**Post date:** [April 23, 2018, 5:14pm UTC](https://help.nextcloud.com/t/force-directory-and-file-permissions/30540/7 "2018-04-23T17:14:52Z")

</div>

> [@tlaughlin](#):
>
> Makes since that I could change the webserver group to one that has shared permissions

I thought we mentioned that as probable solution already:

> [@Schmu](#):
>
> run the web server with that group

> [@MichaIng](#):
>
> Nextcloud cannot influence with what “system” user and group files are created. They are created by the webserver according to its user and group settings within e.g. /etc/apache2/apache.conf

Or do I misunderstand you and you explicitly don’t want to run the web server / PHP handler with another group?  
When you run apache (which we don’t know because there was no description what software you run) refer to the advise Michalng gave. If you’re running nginx you could change the group setting in php-fpm.ini:

> group [string]  
> Unix group of FPM processes. If not set, the default user’s group is used  
> ([PHP: Configuration - Manual](http://php.net/manual/en/install.fpm.configuration.php))

---

<div class="post-metadata">

**Author:** ![tlaughlin](https://help.nextcloud.com/user_avatar/help.nextcloud.com/tlaughlin/32/8807_2.png) [@tlaughlin](https://help.nextcloud.com/u/tlaughlin)\
**Post date:** [April 23, 2018, 6:14pm UTC](https://help.nextcloud.com/t/force-directory-and-file-permissions/30540/8 "2018-04-23T18:14:54Z")

</div>

chmod g+s is successfully applying the correct group for new folders however they are created without group having write permission.

Short version of this question would be to ask where in nextcloud is the folder created and could I add to that setting permissions correctly.

I mean I understand they are created with the www-data user and group normally but why wouldn’t I be able to set group write permissions as well.

This is an apache setup on ubuntu btw with ZFS pool.

TL

---

<div class="post-metadata">

**Author:** ![Schmu](https://help.nextcloud.com/user_avatar/help.nextcloud.com/schmu/32/7823_2.png) [@Schmu](https://help.nextcloud.com/u/Schmu)\
**Post date:** [April 23, 2018, 7:02pm UTC](https://help.nextcloud.com/t/force-directory-and-file-permissions/30540/9 "2018-04-23T19:02:25Z")

</div>

The permissions are defined by umask. If you change the umask value to 007 for the web server user that should work. Your current value is either 022 or 027.

---

<div class="post-metadata">

**Author:** ![tlaughlin](https://help.nextcloud.com/user_avatar/help.nextcloud.com/tlaughlin/32/8807_2.png) [@tlaughlin](https://help.nextcloud.com/u/tlaughlin)\
**Post date:** [April 23, 2018, 7:28pm UTC](https://help.nextcloud.com/t/force-directory-and-file-permissions/30540/10 "2018-04-23T19:28:25Z")

</div>

That’s what I wanted! Just changed the umask in apache’s envvars and everythings working the way I want.

Thanks!

---

<div class="post-metadata">

**Author:** ![Ayslan\_A](https://help.nextcloud.com/user_avatar/help.nextcloud.com/ayslan_a/32/45037_2.png) [@Ayslan\_A](https://help.nextcloud.com/u/Ayslan_A)\
**Post date:** [August 8, 2022, 11:52pm UTC](https://help.nextcloud.com/t/force-directory-and-file-permissions/30540/11 "2022-08-08T23:52:04Z")

</div>

Hey. Could you tell me how you did to change the umask? I’m with the same goal.

I edited the file \lib\private\Files\Storage\Local.php and changed the umask to 007.

How did you do it?

---

<div class="post-metadata">

**Author:** ![xplreitr](https://help.nextcloud.com/user_avatar/help.nextcloud.com/xplreitr/32/46785_2.png) [@xplreitr](https://help.nextcloud.com/u/xplreitr)\
**Post date:** [October 21, 2022, 9:55am UTC](https://help.nextcloud.com/t/force-directory-and-file-permissions/30540/12 "2022-10-21T09:55:35Z")

</div>

For those interested it was addressed in version 25+  
Add to [config.php](https://docs.nextcloud.com/server/latest/admin_manual/configuration_server/config_sample_php_parameters.html#) `'localstorage.umask' => 002,`  
While umask will still return 0022, new folders will be given group write permissions.  
I think there is also a plan to backport it to 24?

---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [December 4, 2024, 6:55am UTC](https://help.nextcloud.com/t/force-directory-and-file-permissions/30540/13 "2024-12-04T06:55:10Z")

</div>


