Developer forum

Forum » Dynamicweb 10 » Non admin user with read access can modify permissions in backend

Non admin user with read access can modify permissions in backend

Bjarki Óskarsson
Reply

I created a new User (not Admin or Administrator), with "Allow backend login" = true, and put him in a group that only has Read access to certain parts of the Content, Assets and Users sections, the permissions work correctly in limiting the users access to the Admin portal, however for the parts the user has access to he´s able to access the permissions view and modify everyone´s permission levels on that section, f.e. he can give himself and others the All permission and also remove permissions.

 

 

backend-permission.png

Replies

 
Nicolai Pedersen Dynamicweb Employee
Nicolai Pedersen
Reply

Hi Bjarki

Thank you for the report. I have sent this to QA for verification. We will get back.

BR Nicolai

 
Oleg Rodionov Dynamicweb Employee
Oleg Rodionov
Reply

Hi,

I've checked the issue with Swift2 solution based on last R0 (10.23.2) version and was not able to reproduce it. First check: I've created new user group, default permissions was not set for it in edit form, added new regular user has backend access as mentioned above. Set "Read" permissions on Content, Assets and Users areas via navigation meny. So, if I logged by the user in backend then I have only read access to the areas navigation and items inside them with appropriate meny item set, no "Permissions" item shown on item in navigation, list or Actions menu (OK). Note if I set "All" permission for the areas and set "Read" for an items inside it then the item does not have "Permissions" as well (OK). Second check: remove the permissions set in previous scenario, edit the user group, set default permissions  = "Read" and save, login by the user in backed, check actual permissions on the areas and its item inside it - the same results as with previous scenario are (OK).

The description and screenshot above is not informative in fact, since it does not say about default permissions on the group as well as about other parent ones could has full permissions for the areas etc. 

BR, Oleg QA    

 

You must be logged in to post in the forum