I did a fresh installation of OpenScholar (version: 2.0-beta14; flavor: Scholar Personal Sites ).
I created a new user (julie), a scholar web site (http://example.com/julie), and a page (http://example.com/julie/pages/test)
I upgraded the Organic Groups module (from the default version og-6.x.2.1) to og-6.x.2.3.
I did this, because there is a security vulnerability associated with the Organic Groups module (version < og-6.x.2.3). The advisory reads:
The module's Views integration does not filter out information from display
groups to which the current user does not have access, exposing private group
titles and the fact that the content is associated with the group.
I log in as this user, and go to the control panel (http://example.com/julie/cp/build/features). I see the error:
You are not authorized to access this page.
This same error appears for all control panel menu options (e.g. appearance, settings, content).
I log in as the 'administrative' user, and I can view the content, but if I try to edit the page (http://example.com/julie/node/2/edit), I see the error:
Access denied
You are not authorized to access this page.
This is repeatable by following the steps above. The error occurs also for version og-6.x-2.2.
I checked the 'Organic Groups' module Issues, but I cannot find an access problem related to a upgrade. Problably the closest Issue is:
Views filter "Organic groups: Groups" broken after update to 2.2 (http://drupal.org/node/1451884)
Comments
Comment #1
andrej235 commentedI second that report. Same problem here.
DON'T DOWNGRADE! It will break your site.
Comment #2
ferdi commentedPlease dont upgrade modules unless you know what you are doing. We are not using OG private groups in OpenScholar, so the security issue with OG is not that urgent.
thanks!
Comment #3
miriku commentedThanks ferdi. Any advice for those of us who read this note after already patching and now cannot use administrator editing accounts?