Jump to content

Permissions management


Jujuwar

Recommended Posts

First, I'm sorry if this topic is unclear ...

Yesterday, I've opened a ticket because one member can't see in the unread AS the content of one forum, even if he can read this forum.

The problem was that this forum (eg. Forum3) was in a category like bellow:

  • Category 1
    • Forum 1
    • Forum 2
    • Forum 3

The member has access to Category 1, Forum 1 and Forum 2 via his group.
The member also has a secondary group to have access to Forum 3.

The secondary group in question doesn't have the permission to see Category 1, but has the member have access to Category 1 via his group, no problem to see Forum 3. But even if like that he can see the Forum 3, the AS doesn't think he can view the new content.

 

What I "propose", as suggested in my ticket 948812, is that you need to make the permissions management more... user-friendly? Maybe you can detect if there is some "weird" configuration. It seems illogical to have the permission to read the Forum 3 if you don't have read permission on the Category 1.

Maybe you should verify the permissions in the same way when we look a forum and when we look an AS?

Link to comment
Share on other sites

I sadly think the permissions are correct here.

Technically if you put that member in the secondary group as their primary and they couldn't see category 1 then they would not be able to see ANY of those forums and so as such I think the permissions are being read correctly. Basically if you aren't able to see the container how can you open it to see what's inside of it?

Link to comment
Share on other sites

11 minutes ago, Morrigan said:

I sadly think the permissions are correct here.

Technically if you put that member in the secondary group as their primary and they couldn't see category 1 then they would not be able to see ANY of those forums and so as such I think the permissions are being read correctly. Basically if you aren't able to see the container how can you open it to see what's inside of it?

The problem is that the member can read the container as his primary group set the permission. So, his problem was that he was able to read new topics in the "private forum" via the secondary group, but he can't see new topics via AS (because the secondary group didn't include the permission to read the category, but his primary does).

Link to comment
Share on other sites

I understand the issue but the permissions are still correct. Permissions read:

Container > Forum

Just because they had a supplementary permission that provided them access to that forum that doesn't mean that, within that group, they had access to the container. As I said originally, IF you make that their primary group they wouldn't be able to see the category at all so the permissions are doing as they are told. You told the permissions that ONLY if they have access to the primary group forums do they get access to this secondary group forum but that doesn't negate that WITHOUT the primary group the secondary group doesn't have permissions to access that category.

 

Edit: I'm going to add to this and use something like classified information. Just because you are granted access to a classified file (forum) doesn't mean that you have access to all classified files (forums) without being granted that access at a higher level (category) as well as specifically to those classified files (forums).

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...