Makes roles the only Roles holding ReceiveEvents on AuditEventType and on every subtype loaded so
far, so that event MonitoredItems deliver Audit Events to their Sessions alone (OPC 10000-2 v1.05.06 §6.7:
"Administrative AccessRestrictions should also be used to control Audit Events").
Only the ReceiveEvents bit is rewritten: every other permission a type declares stays as its
nodeset wrote it. Opc.Ua.NodeSet2.xml already grants ReceiveEvents to SecurityAdmin alone on the
standard audit types, so the default leaves those unchanged; a subtype that declares nothing
(several companion "...AuditEventType"s do) gets the same shape: Browse and Read for every Session,
ReceiveEvents for roles. A subtype added after this runs (Namespace.addEventType) is not covered
and needs RolePermissions of its own.
Naming the Anonymous Role hands Audit Events to every Session again.
Makes
rolesthe only Roles holding ReceiveEvents on AuditEventType and on every subtype loaded so far, so that event MonitoredItems deliver Audit Events to their Sessions alone (OPC 10000-2 v1.05.06 §6.7: "Administrative AccessRestrictions should also be used to control Audit Events").Only the ReceiveEvents bit is rewritten: every other permission a type declares stays as its nodeset wrote it. Opc.Ua.NodeSet2.xml already grants ReceiveEvents to SecurityAdmin alone on the standard audit types, so the default leaves those unchanged; a subtype that declares nothing (several companion "...AuditEventType"s do) gets the same shape: Browse and Read for every Session, ReceiveEvents for
roles. A subtype added after this runs (Namespace.addEventType) is not covered and needs RolePermissions of its own.Naming the Anonymous Role hands Audit Events to every Session again.