Security policy for user settings ?

Author Message

Kevin Gaudin

Wednesday 12 November 2008 1:11:54 am

Hello,

I'm trying to setup a specific group of users which are allowed to manage users and groups and nothing else (eZ Pub. v 4.0.0).

I'm using the following policies :

content / create / Subtree( Users ) , Class( User ) , Section( Users ) , ParentClass( User group )
content / create / Subtree( Users ) , Class( User group ) , Section( Users )
content / edit / Subtree( Users ) , Class( User group , User ) , Section( Users )
content / read / Subtree( Users ) , Section( Users )
content / move / No limitations
content / manage_locations / Subtree( Users ) , Class( User ) , Section( Users )
content / remove / Subtree( Users ) , Class( User group , User ) , Section( Users )
user / login / SiteAccess( admin , fr , en )

I can login to the backoffice, create/edit/move users, but can't go to the users settings form... this might not be a real problem as the only possible action in this form is to activate/deactivate the account, but can anyone tell me what security policy has to be set up to authorize access to this form ?

Twitter: @kevingaudin

Kristof Coomans

Monday 17 November 2008 6:35:29 am

Hi Kevin

You need to use the policy user/preferences. Note however this policy does not respect any limitations, so it will allow access to any user's settings (activate/deactivate).

See http://ez.no/doc/ez_publish/technical_manual/4_0/reference/modules/user/views/setting and http://ez.no/doc/ez_publish/technical_manual/4_0/reference/modules/user/views/preferences

independent eZ Publish developer and service provider | http://blog.coomanskristof.be | http://ezpedia.org

Powered by eZ Publish™ CMS Open Source Web Content Management. Copyright © 1999-2014 eZ Systems AS (except where otherwise noted). All rights reserved.

eZ debug

Timing: Jan 18 2025 11:25:57
Script start
Timing: Jan 18 2025 11:25:57
Module start 'layout'
Timing: Jan 18 2025 11:25:57
Module start 'content'
Timing: Jan 18 2025 11:25:59
Module end 'content'
Timing: Jan 18 2025 11:25:59
Script end

Main resources:

Total runtime1.5860 sec
Peak memory usage4,096.0000 KB
Database Queries54

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0058 587.9375152.6250
Module start 'layout' 0.00580.0034 740.562539.4453
Module start 'content' 0.00921.5751 780.0078530.5781
Module end 'content' 1.58430.0017 1,310.58598.1563
Script end 1.5860  1,318.7422 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00310.1974160.0002
Check MTime0.00130.0805160.0001
Mysql Total
Database connection0.00110.068010.0011
Mysqli_queries1.540197.1059540.0285
Looping result0.00060.0352520.0000
Template Total1.549197.720.7746
Template load0.00210.130220.0010
Template processing1.547197.542520.7735
Template load and register function0.00010.006310.0001
states
state_id_array0.00190.117010.0019
state_identifier_array0.00200.126820.0010
Override
Cache load0.00150.0934140.0001
Sytem overhead
Fetch class attribute can translate value0.00060.036920.0003
Fetch class attribute name0.00090.056540.0002
XML
Image XML parsing0.00120.073120.0006
class_abstraction
Instantiating content class attribute0.00000.002140.0000
General
dbfile0.00090.0542220.0000
String conversion0.00000.000640.0000
Note: percentages do not add up to 100% because some accumulators overlap

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1node/view/full.tplfull/forum_topic.tplextension/sevenx/design/simple/override/templates/full/forum_topic.tplEdit templateOverride template
2content/datatype/view/ezimage.tpl<No override>extension/sevenx/design/simple/templates/content/datatype/view/ezimage.tplEdit templateOverride template
2content/datatype/view/ezxmltext.tpl<No override>extension/community_design/design/suncana/templates/content/datatype/view/ezxmltext.tplEdit templateOverride template
3content/datatype/view/ezxmltags/paragraph.tpl<No override>extension/ezwebin/design/ezwebin/templates/content/datatype/view/ezxmltags/paragraph.tplEdit templateOverride template
1content/datatype/view/ezxmltags/literal.tpl<No override>extension/community/design/standard/templates/content/datatype/view/ezxmltags/literal.tplEdit templateOverride template
1print_pagelayout.tpl<No override>extension/community/design/community/templates/print_pagelayout.tplEdit templateOverride template
 Number of times templates used: 10
 Number of unique templates used: 6

Time used to render debug report: 0.0004 secs