Site
Web
Home
Modules
Advanced Articles
Overview
Demo - Advanced Articles
Demo - Site Wide Articles
Demo - Articles Slides Show
Demo - Articles Search
Demo - Articles Archive
Demo - Articles By Category
Facility Booking
Overview
Demo
Content Manager
Overview
Content Manager - Demo
Content Approval - Demo
Event Calendar
Overview
Event Calendar - Demo
Satellite Module - Demo
Personal Events - Demo
Flash Calendar - Demo
Events Calendar Search - Demo
Token Replace Reference
Default Templates
Download Resources
Upgrade Policy
Excel Template Instruction
Affiliate Modules
Car Listing
Overview
Demo - Car Listing Search
Demo - Car Listing - Featured Car Listing
Purchase
Online Payment
Download
Support
User Forum
License Activation
FAQs
Contact Us
You are here:
Support
>
User Forum
Register
|
Login
Invenmanager User Forum
Unanswered
Active Topics
Forums
Search
Forums
>
Content Manager
>
Technical Support
Security Flaw - Editors are also Administrators ?
Last Post 30 Jul 2009 04:12 PM by Inven Manager. 9 Replies.
Sort:
Oldest First
Most Recent First
Prev
Next
You are not authorized to post a reply.
Author
Messages
john faulkner
New Member
Posts:20
29 Jul 2009 10:31 AM
Hello
I like your product and its ease of use but there seems to be a security problem. If you create a content editor who has the abilty to change content they also have the ability to change all Content Manager Types and settings - so they are free to allocate a new type with a new approval process to their module or worse change an existng process which affects all other modules ? - shouldnt there be a seperate admin module for administering content Types ie the Workflow Process which is NOT available to Content Editors.
Or have I misundertood the set up ?
thanks
John
Inven Manager
Senior Member
Posts:6765
29 Jul 2009 03:59 PM
Not really. The content editor should only have Edit permission to the module. The Content Types is only accessible by Admin users.
You can try login as Editor/editor, from the Content Manager demo page.
Thanks.
========================================
Delivering high value DotnetNuke Modules to save your time and resources
john faulkner
New Member
Posts:20
29 Jul 2009 04:15 PM
OK thanks- yep I see that works if the content editor only has view acces to the page, unfortunately our editors need to have edit (full access) to pages so they can create new modules and sub pages etc. This setting then overrides anything else and gives them full permission on the Content Module - is there anyway round this ? (I tried changing the module definition settings for Content Workflow etc to ADMIN but this made no difference)
Inven Manager
Senior Member
Posts:6765
30 Jul 2009 03:42 AM
You can change the permission to HOST at the module definition settings. In this case, only Host Account can edit the Content Types.
You change to Admin no difference because when you give the user Editor to the page, he will have Admin permission to all the modules on that page.
Thanks
========================================
Delivering high value DotnetNuke Modules to save your time and resources
john faulkner
New Member
Posts:20
30 Jul 2009 09:07 AM
Thanks - have tried changing Manage Routing and Edit Routing to Host but it didnt make any difference. The editor still has full permission over the module on the page. Am i doing something wrong ?
Inven Manager
Senior Member
Posts:6765
30 Jul 2009 09:12 AM
I don't think the Editor still can access the Edit Routing page if you changed that to HOST permission.
Unless the Editor is a host account?
========================================
Delivering high value DotnetNuke Modules to save your time and resources
john faulkner
New Member
Posts:20
30 Jul 2009 09:36 AM
OK thanks my mistake - The content edit/routing items still appear on the popup menu but you get access denied when you try and enter the page.
I have also noticed 2 new option appear on the page settings under permissions - Submit Tab and Approve Tab could you tell me what they do ?
Inven Manager
Senior Member
Posts:6765
30 Jul 2009 02:32 PM
You do not need that...
========================================
Delivering high value DotnetNuke Modules to save your time and resources
john faulkner
New Member
Posts:20
30 Jul 2009 03:05 PM
Is there someway I can get rid of them - they will confuse our editors
Inven Manager
Senior Member
Posts:6765
30 Jul 2009 04:12 PM
Can you upload a screen shot here? I belive it is not provided by Content Manager module. thanks.
========================================
Delivering high value DotnetNuke Modules to save your time and resources
You are not authorized to post a reply.
General
--General Questions
Event Calendar & Registration
--General Questions
--Technical Support
--Feature Request
--Localization Resources
Content Manager
--Technical Support
--Feature Request
Advanced Articles
--Technical Support
--Feature Request
Facility Booking
--Technical Support
--Feature Request
Car Listing Module
--Technical Support
--Feature Request
Forums
>
Content Manager
>
Technical Support
Active Forums 4.1
Home
|
Purchase
|
Download
|
FAQs
|
Contact Us
Privacy Statement
|
Terms Of Use
Copyright (c) 2009 InvenManager Solutions.