The default permission is to allow access to all users who can "access administration pages" but this is too liberal for many environments.

For example, we have a multi-tiered role setup consisting of Admin (user 1), Site Managers, Content Managers (edit all nodes), Employment Managers (one content type only).

By default, our lower-level Managers need to be have the "Access administration permissions" role to access site reports etc but definitely should not have access to the Authorize.net settings.

Our fix was to change the default access permission requirement to "edit webforms" as anyone with the privilege of being able to edit the structure of a form is (more likely to be) allowed to see/edit the authorize.net settings.

Alternatively, this module is probably separate/important enough to warrant it's own "Administer authorize.net webform settings" permission...

Comments

dzepol’s picture

+1 for adding an additional permission specific for this module.

obsidiandesign’s picture

Assigned: Unassigned » obsidiandesign
Status: Active » Fixed

I've committed this into the module; I'm going to try and fix several of the outstanding issues before rolling a new version.

Bryan O'Shea
Obsidian Design

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.