Users able to publish any content regardless of permissons via CMF's 'Update Options'.

smithcman - June 8, 2009 - 23:54
Project:Content Management Filter
Version:6.x-1.6
Component:Miscellaneous
Category:support request
Priority:normal
Assigned:Unassigned
Status:duplicate
Description

I absolutely could be missing something, but I've noticed that I can create a role, give it the 'filter and manage site content' permission, explicitly give it no access to a content type (e.g. 'Page') in the node module section of permissions, but still find that a user in this role can publish and unpublish page content (any content, really) via CMF's 'Update Options.' The user in this role can see all content in the list (as covered in other issues that have been submitted), but he is unable to edit or delete. No such restriction seems to apply to publishing and unpublishing. Am I misunderstanding how this works?

Thanks in advance for any info.

#1

smithcman - June 9, 2009 - 00:01

Guess I should mention:

Drupal 6.12 (noticed this in 6.11, too)
CMF 6.x-1.6
Have rebuilt permissions and cleared the cache repeatedly to see if it helps

#2

smithcman - June 9, 2009 - 00:04
Title:Users able to publish any content regarldess of permissons via CMF's 'Update Options'.» Users able to publish any content regardless of permissons via CMF's 'Update Options'.

#3

tuffnatty - July 1, 2009 - 09:15

subscribing

#4

NancyDru - July 16, 2009 - 16:27
Status:active» duplicate

I am marking this as a duplicate of #328869: CMF and access management.

 
 

Drupal is a registered trademark of Dries Buytaert.