Closed (won't fix)
Project:
Forum Access
Version:
6.x-1.4
Component:
User interface
Priority:
Major
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
16 Aug 2010 at 16:40 UTC
Updated:
24 Aug 2010 at 22:04 UTC
Jump to comment: Most recent file
Comments
Comment #1
salvisDoes the role that tries to access these links have View access to the forums/containers?
Even if you have 'administer forums', you cannot administer forums to which you don't have View access (because you could then grant yourself access). The idea here is that user 1 can withhold View access to super-confidential forums, so that the 'administer forums' permission is not an all-powerful one.
Comment #2
thrakkor commentedafter installing this update, I (as admin) cannot even view the forum pages.. I can view forum topics however. I have access to all views. Reverting to previous release returns to previous expected behavior.
Comment #3
salvisAre you saying that user 1 gets 'access denied' on the forum/TID pages? That's not what I'm seeing.
Please go to admin/content/forum/edit/forum/TID and check the "Permissions information" against what you have.
Comment #4
particle commentedI'm seeing something similar. This has opened a huge security hole.
1) I have a Global Admin role which duplicates user 1 with slightly less privileges. This role is now denied View permission (it's in italics now and it can't be enabled).
2) I completely lost control of two hidden forums until the user 1 account added my account (it's a Global Admin) as a moderator to these forums.
3) We specifically disable "delete any forum topic" and "delete own forum topics" in the main forum permissions to prevent anyone from deleting anything (moderators could previously only move threads to a hidden forum). Now all the roles which include a forum moderator have delete checked in the forum preferences and it's grayed out so it can't be disabled. The bottom line is that the Forum Access role permissions are being automatically granted to other roles in a way that are contrary to the site's security policy and are non-revocable. THIS IS A SECURITY HOLE. At least make delete optional.
See attached screen shot.
Comment #5
salvis@particle: WAIT!
You are quick to use the term security hole.
I can't deal with this in this way. If you think one of the three issues that you mention is related to the topic of this thread (probably 2)), then restate it here and please create two new threads for the other two.
Hover your mouse over the items and read what it says. Also read the explanations in the (collapsed) "Permissions information" fieldset. For each issue state what permissions the roles in question have and how you expect FA to behave.
Comment #6
salvisIn fact, since the first two posters are apparently unwilling to work out the details and #4 further muddies the water, I'll just close this thread and ask each of you who is willing to follow through to open new issues (one issue per issue, please).