Forums / Install & configuration / Issue: Editor has Administrator priviliges. Solution?

Issue: Editor has Administrator priviliges. Solution?

Author Message

elliot smelliot

Monday 19 May 2003 11:26:48 am

Per document, http://www.ez.no/developer/ez_publish_3/bug_reports/urgent_security_risk_privilege_escalation_in_default_install, I am trying to run a student newspaper at my High School, and I would like reporters and editors to be able to add and modify articles (content), but whenever I try to take the “Users” permission away from the Editor’s role, it doesn’t allow the Editor to log in. I view this as a problem, since I don’t want any editor capable of taking over the whole system.

On the message board, this was recommended:

“Re: Roles and user 'drafts' help needed.
To fix proplem with drafts you need to add new line at kernel/content/module.php line 194.
"functions" => array( 'create' ),
after that modification user will be able to access”

Paul Borgermans

Monday 19 May 2003 12:29:42 pm

You must the editors al least a login right as one of the rules in the role fro them. You mustdisallow editing content of class user . Make sure you also apply the security patch posted earlier today.

hth

Paul

eZ Publish, eZ Find, Solr expert consulting and training
http://twitter.com/paulborgermans

elliot smelliot

Tuesday 17 June 2003 3:54:05 pm

This issue is still truly unresolved. Can anyone make a suggestion or write out step by step instructions to fix this horrible issue. Thx.

eZ debug

Timing: Jan 31 2025 01:21:35
Script start
Timing: Jan 31 2025 01:21:35
Module start 'content'
Timing: Jan 31 2025 01:21:35
Module end 'content'
Timing: Jan 31 2025 01:21:35
Script end

Main resources:

Total runtime0.3014 sec
Peak memory usage8,192.0000 KB
Database Queries141

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0074 588.1797370.2656
Module start 'content' 0.00740.0182 958.44531,001.6250
Module end 'content' 0.02560.2757 1,960.07033,890.5703
Script end 0.3013  5,850.6406 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00531.7707200.0003
Check MTime0.00140.4602200.0001
Mysql Total
Database connection0.00080.275110.0008
Mysqli_queries0.161353.51981410.0011
Looping result0.00170.56841390.0000
Template Total0.275191.310.2751
Template load0.00090.306610.0009
Template processing0.274290.984510.2742
Override
Cache load0.00050.171510.0005
Sytem overhead
Fetch class attribute can translate value0.00311.032310.0031
XML
Image XML parsing0.00040.122510.0004
General
dbfile0.02889.5528200.0014
String conversion0.00000.002130.0000
Note: percentages do not add up to 100% because some accumulators overlap

CSS/JS files loaded with "ezjscPacker" during request:

CacheTypePacklevelSourceFiles
CSS0extension/community/design/community/stylesheets/ext/jquery.autocomplete.css
extension/community_design/design/suncana/stylesheets/scrollbars.css
extension/community_design/design/suncana/stylesheets/tabs.css
extension/community_design/design/suncana/stylesheets/roadmap.css
extension/community_design/design/suncana/stylesheets/content.css
extension/community_design/design/suncana/stylesheets/star-rating.css
extension/community_design/design/suncana/stylesheets/syntax_and_custom_tags.css
extension/community_design/design/suncana/stylesheets/buttons.css
extension/community_design/design/suncana/stylesheets/tweetbox.css
extension/community_design/design/suncana/stylesheets/jquery.fancybox-1.3.4.css
extension/bcsmoothgallery/design/standard/stylesheets/magnific-popup.css
extension/sevenx/design/simple/stylesheets/star_rating.css
extension/sevenx/design/simple/stylesheets/libs/fontawesome/css/all.min.css
extension/sevenx/design/simple/stylesheets/main.v02.css
extension/sevenx/design/simple/stylesheets/main.v02.res.css
JS0extension/ezjscore/design/standard/lib/yui/3.17.2/build/yui/yui-min.js
extension/ezjscore/design/standard/javascript/jquery-3.7.0.min.js
extension/community_design/design/suncana/javascript/jquery.ui.core.min.js
extension/community_design/design/suncana/javascript/jquery.ui.widget.min.js
extension/community_design/design/suncana/javascript/jquery.easing.1.3.js
extension/community_design/design/suncana/javascript/jquery.ui.tabs.js
extension/community_design/design/suncana/javascript/jquery.hoverIntent.min.js
extension/community_design/design/suncana/javascript/jquery.popmenu.js
extension/community_design/design/suncana/javascript/jScrollPane.js
extension/community_design/design/suncana/javascript/jquery.mousewheel.js
extension/community_design/design/suncana/javascript/jquery.cycle.all.js
extension/sevenx/design/simple/javascript/jquery.scrollTo.js
extension/community_design/design/suncana/javascript/jquery.cookie.js
extension/community_design/design/suncana/javascript/ezstarrating_jquery.js
extension/community_design/design/suncana/javascript/jquery.initboxes.js
extension/community_design/design/suncana/javascript/app.js
extension/community_design/design/suncana/javascript/twitterwidget.js
extension/community_design/design/suncana/javascript/community.js
extension/community_design/design/suncana/javascript/roadmap.js
extension/community_design/design/suncana/javascript/ez.js
extension/community_design/design/suncana/javascript/ezshareevents.js
extension/sevenx/design/simple/javascript/main.js

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1pagelayout.tpl<No override>extension/sevenx/design/simple/templates/pagelayout.tplEdit templateOverride template
 Number of times templates used: 1
 Number of unique templates used: 1

Time used to render debug report: 0.0001 secs