Register   Login
     
  Latest Posts  
RE: Personal Items - diary
by robax on 1/07/2009 1:52 AM
RE: small bug with 00.07.19 - Articles with future date counted in Archives
by smcculloch on 1/07/2009 1:49 AM
RE: Search Wildcard Problem!
by smcculloch on 1/07/2009 1:49 AM
RE: ISINROLE feature
by smcculloch on 1/07/2009 1:47 AM
RE: Latest Photos play/pause language bits
by smcculloch on 1/07/2009 1:47 AM
RE: BUG: [LINK] token generates duplicate url and spoiled SEO
by smcculloch on 1/07/2009 1:46 AM
RE: BUG: [LINK] token generates duplicate url and spoiled SEO
by smcculloch on 1/07/2009 1:45 AM
RE: Product Discontinued?
by smcculloch on 1/07/2009 1:43 AM
RE: Sorting images in an Album
by smcculloch on 1/07/2009 1:43 AM
RE: Bug and suggestion to fix it --> GRAVATAR: uppercase and lowercase
by smcculloch on 1/07/2009 1:41 AM
  Forums  
Subject: Security bug: Can view articles even if user is not allowed
Prev Next
You are not authorized to post a reply.

Author Messages
Mariette KnapUser is Offline
Registered Users
Nuke Master
Nuke Master
Posts:650


2/02/2006 8:11 AM  

This is serious. Similar to http://www.smcculloch.net/Forums/tabid/118/forumid/4/postid/7350/view/topic/Default.aspx. I have created a module on a page with News Articles and allowed only one role to view the content. If an unauthenticated user goes to: http://www.smallbizserver.net/Default.aspx?tabid=268 he does not see the module but if he goes to one of the documents inside the NewsArticle module like: http://www.smallbizserver.net/Default.aspx?tabid=268 he can see the content. This means that this content is also indexed by search engines and I definately don't want that.

This absolutely unacceptable. I just started to move all my documents to news articles and I sure hope Scott can fix this asap.



Subscribe for great articles and howtos. Get unlimited access to all content.
Mariëtte Knap
www.smallbizserver.net
Mariette KnapUser is Offline
Registered Users
Nuke Master
Nuke Master
Posts:650


2/02/2006 11:29 AM  

I just thought of a very simple solution for this problem. In the Subscribtion Tools you have created a module that allows one to show content based on the role the user is in. This would be the perfect solution for me.

On my site I have articles. If the summary would be available to all users and the article itself can be organized in the way the Subscription Tools work I will be very happy. If a user is not a Subscriber he will see the summary but as soon as he clicks on 'Read more' there will be a teaser to become a Member. If a member logs in to the same articles the full content will be shown.

I hope this helps.



Subscribe for great articles and howtos. Get unlimited access to all content.
Mariëtte Knap
www.smallbizserver.net
Nick ClementsUser is Offline
Gold Membership
Nuke Active Member
Nuke Active Member
Posts:29

2/08/2006 10:11 PM  
I would assume that Scott will be looking to fix this 'bug' as it was certainly working as intended a few versions ago. Then you wouldn't need that workaround.

Regards,
Nick
Scott McCullochUser is Offline
Administrators
Nuke Master
Nuke Master
Posts:12784


2/09/2006 4:39 AM  

There will be some changes to the way groups work in news articles (similar to active forums), so you can restrict access to the article, summary, full article by role.


Scott McCulloch
Site Administrator
Mariette KnapUser is Offline
Registered Users
Nuke Master
Nuke Master
Posts:650


2/09/2006 7:48 AM  
Can't wait for it


Subscribe for great articles and howtos. Get unlimited access to all content.
Mariëtte Knap
www.smallbizserver.net
Alex ShirleyUser is Offline
Gold Membership
Nuke Wiz
Nuke Wiz
Posts:164

10/06/2006 4:31 PM  
Any ETA on this?
I'm beginning a new commercial website that will use news articles (hopefully) and this fix will be essential before I can launch.

Many thanks!

Alex
Scott McCullochUser is Offline
Administrators
Nuke Master
Nuke Master
Posts:12784


10/06/2006 5:20 PM  
Currently, the viewing articles is restricted by:-

* IsSecure set (and the person not being in a role)
* No access permissions to the module (via Module Settings)

There is currently no category based permissions, I'm assuming this is what you need? Mariette uses the IsSecure part of the module to secure articles.

Scott McCulloch
Site Administrator
Mariette KnapUser is Offline
Registered Users
Nuke Master
Nuke Master
Posts:650


10/07/2006 1:02 AM  
Yes, works very well.


Subscribe for great articles and howtos. Get unlimited access to all content.
Mariëtte Knap
www.smallbizserver.net
You are not authorized to post a reply.
Forums > Modules > News Articles > Security bug: Can view articles even if user is not allowed



ActiveForums 3.7