Anonymous User can edit all comments

Author Message

Ekkehard Dörre

Friday 25 June 2004 5:15:01 am

Hi,
I use article comments with anonymous user can post and content approval by admin.
Problem: In role they need content create and edit.
So any anonymous visitor can edit all done comments from other visitors.
Any ideas, workaround?

Thanks, ekke

http://www.coolscreen.de - Over 40 years of certified eZ Publish know-how: http://www.cjw-network.com
CJW Newsletter: http://projects.ez.no/cjw_newsletter - http://cjw-network.com/en/ez-publ...w-newsletter-multi-channel-marketing

Ekkehard Dörre

Sunday 27 June 2004 3:12:04 am

I found this bug notice by Volker Lenz

http://ez.no/community/bug_reports/how_to_allow_simple_posting_for_anonymous_users_no_login_requirements

Is this hack the only workaround?

Greetings ekke

http://www.coolscreen.de - Over 40 years of certified eZ Publish know-how: http://www.cjw-network.com
CJW Newsletter: http://projects.ez.no/cjw_newsletter - http://cjw-network.com/en/ez-publ...w-newsletter-multi-channel-marketing

Ekkehard Dörre

Tuesday 29 June 2004 5:46:06 am

This hack works for 3.3.5 too,

Thanks to Volker, before it was a big security hole.

Greetings, ekke

http://www.coolscreen.de - Over 40 years of certified eZ Publish know-how: http://www.cjw-network.com
CJW Newsletter: http://projects.ez.no/cjw_newsletter - http://cjw-network.com/en/ez-publ...w-newsletter-multi-channel-marketing

Volker Lenz

Thursday 09 September 2004 8:03:46 am

BTW my hack works with ezp 3.4.x, too.
And I hope that this hack will soon become a part of the ez standard, because I really dislike copying-pasting my codepieces in frequently changing versions of ezcontentobject.php :-(

Powered by eZ Publish™ CMS Open Source Web Content Management. Copyright © 1999-2014 eZ Systems AS (except where otherwise noted). All rights reserved.

eZ debug

Timing: Jan 18 2025 10:31:36
Script start
Timing: Jan 18 2025 10:31:36
Module start 'layout'
Timing: Jan 18 2025 10:31:36
Module start 'content'
Timing: Jan 18 2025 10:31:36
Module end 'content'
Timing: Jan 18 2025 10:31:36
Script end

Main resources:

Total runtime0.0330 sec
Peak memory usage2,048.0000 KB
Database Queries3

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0105 588.0313152.6406
Module start 'layout' 0.01050.0040 740.671939.4766
Module start 'content' 0.01450.0156 780.148493.3359
Module end 'content' 0.03010.0028 873.484434.3047
Script end 0.0329  907.7891 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00319.3750140.0002
Check MTime0.00123.7315140.0001
Mysql Total
Database connection0.00226.666810.0022
Mysqli_queries0.005416.406330.0018
Looping result0.00000.078810.0000
Template Total0.00206.110.0020
Template load0.00113.281710.0011
Template processing0.00092.753810.0009
Override
Cache load0.00072.262810.0007
General
dbfile0.00030.835280.0000
String conversion0.00000.029640.0000
Note: percentages do not add up to 100% because some accumulators overlap

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1print_pagelayout.tpl<No override>extension/community/design/community/templates/print_pagelayout.tplEdit templateOverride template
 Number of times templates used: 1
 Number of unique templates used: 1

Time used to render debug report: 0.0001 secs