After updating forum_access from 6.x-1.3 to version 6.x-1.4, when viewing admin/content/forum the links under 'operations' to 'edit container' and 'edit forum' are missing from all containers or forums that are not public.

Rebuilding permissions did not seem to fix this.

Comments

salvis’s picture

Does the role that tries to access these links have View access to the forums/containers?

Even if you have 'administer forums', you cannot administer forums to which you don't have View access (because you could then grant yourself access). The idea here is that user 1 can withhold View access to super-confidential forums, so that the 'administer forums' permission is not an all-powerful one.

thrakkor’s picture

after installing this update, I (as admin) cannot even view the forum pages.. I can view forum topics however. I have access to all views. Reverting to previous release returns to previous expected behavior.

salvis’s picture

Are you saying that user 1 gets 'access denied' on the forum/TID pages? That's not what I'm seeing.

Please go to admin/content/forum/edit/forum/TID and check the "Permissions information" against what you have.

particle’s picture

StatusFileSize
new32.82 KB

I'm seeing something similar. This has opened a huge security hole.

1) I have a Global Admin role which duplicates user 1 with slightly less privileges. This role is now denied View permission (it's in italics now and it can't be enabled).

2) I completely lost control of two hidden forums until the user 1 account added my account (it's a Global Admin) as a moderator to these forums.

3) We specifically disable "delete any forum topic" and "delete own forum topics" in the main forum permissions to prevent anyone from deleting anything (moderators could previously only move threads to a hidden forum). Now all the roles which include a forum moderator have delete checked in the forum preferences and it's grayed out so it can't be disabled. The bottom line is that the Forum Access role permissions are being automatically granted to other roles in a way that are contrary to the site's security policy and are non-revocable. THIS IS A SECURITY HOLE. At least make delete optional.

See attached screen shot.

salvis’s picture

@particle: WAIT!

You are quick to use the term security hole.

I can't deal with this in this way. If you think one of the three issues that you mention is related to the topic of this thread (probably 2)), then restate it here and please create two new threads for the other two.

Hover your mouse over the items and read what it says. Also read the explanations in the (collapsed) "Permissions information" fieldset. For each issue state what permissions the roles in question have and how you expect FA to behave.

salvis’s picture

Status: Active » Closed (won't fix)

In fact, since the first two posters are apparently unwilling to work out the details and #4 further muddies the water, I'll just close this thread and ask each of you who is willing to follow through to open new issues (one issue per issue, please).