Issue: Editor has Administrator priviliges. Solution?

Author Message

elliot smelliot

Monday 19 May 2003 11:26:48 am

Per document, http://www.ez.no/developer/ez_publish_3/bug_reports/urgent_security_risk_privilege_escalation_in_default_install, I am trying to run a student newspaper at my High School, and I would like reporters and editors to be able to add and modify articles (content), but whenever I try to take the “Users” permission away from the Editor’s role, it doesn’t allow the Editor to log in. I view this as a problem, since I don’t want any editor capable of taking over the whole system.

On the message board, this was recommended:

“Re: Roles and user 'drafts' help needed.
To fix proplem with drafts you need to add new line at kernel/content/module.php line 194.
"functions" => array( 'create' ),
after that modification user will be able to access”

Paul Borgermans

Monday 19 May 2003 12:29:42 pm

You must the editors al least a login right as one of the rules in the role fro them. You mustdisallow editing content of class user . Make sure you also apply the security patch posted earlier today.

hth

Paul

eZ Publish, eZ Find, Solr expert consulting and training
http://twitter.com/paulborgermans

elliot smelliot

Tuesday 17 June 2003 3:54:05 pm

This issue is still truly unresolved. Can anyone make a suggestion or write out step by step instructions to fix this horrible issue. Thx.

Powered by eZ Publish™ CMS Open Source Web Content Management. Copyright © 1999-2014 eZ Systems AS (except where otherwise noted). All rights reserved.

eZ debug

Timing: Jan 31 2025 03:23:23
Script start
Timing: Jan 31 2025 03:23:23
Module start 'layout'
Timing: Jan 31 2025 03:23:23
Module start 'content'
Timing: Jan 31 2025 03:23:23
Module end 'content'
Timing: Jan 31 2025 03:23:23
Script end

Main resources:

Total runtime0.0239 sec
Peak memory usage6,144.0000 KB
Database Queries3

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0044 588.3828151.2422
Module start 'layout' 0.00440.0040 739.6250220.7500
Module start 'content' 0.00840.0140 960.3750997.8672
Module end 'content' 0.02240.0015 1,958.242233.9922
Script end 0.0239  1,992.2344 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.002610.7929140.0002
Check MTime0.00104.1933140.0001
Mysql Total
Database connection0.00062.539910.0006
Mysqli_queries0.002610.753130.0009
Looping result0.00000.041810.0000
Template Total0.00114.710.0011
Template load0.00083.521910.0008
Template processing0.00031.186310.0003
Override
Cache load0.00062.511010.0006
General
dbfile0.002912.223280.0004
String conversion0.00000.025940.0000
Note: percentages do not add up to 100% because some accumulators overlap

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1print_pagelayout.tpl<No override>extension/community/design/community/templates/print_pagelayout.tplEdit templateOverride template
 Number of times templates used: 1
 Number of unique templates used: 1

Time used to render debug report: 0.0001 secs