1
jd4x4
WF-Links permissions bug?
  • 2007/10/25 22:02

  • jd4x4

  • Just popping in

  • Posts: 7

  • Since: 2007/10/18


I don't know if this is a problem with WF-Links, or something else but I have two WF-Links categories, one is viewable by anyone and the other only to registered users/admins, etc.

Using the block links everything works as expected, however when an anonymous user views the links page, he can also jump to all links by the submitter, which then shows links in categories he doesn't have permission to.

Is this a bug, or is there someplace where I can turn off a user's ability to see all links by a submitter?

2
script_fu
Re: WF-Links permissions bug?

JD4x4

Can you give us a link to the download of the exact module your speaking of?

Sometimes its better to point to the download. That way we know were talking about the same thing.

3
Catzwolf
Re: WF-Links permissions bug?
  • 2007/10/26 5:38

  • Catzwolf

  • Home away from home

  • Posts: 1392

  • Since: 2007/9/30


I think you are using an older version of this module. there is a newer one by McDonald. Sorry not sure of the actual address, but try searching these forums and you should get a link to it.

4
McDonald
Re: WF-Links permissions bug?
  • 2007/10/26 5:50

  • McDonald

  • Home away from home

  • Posts: 1072

  • Since: 2005/8/15


The original WF-Links 1.03 module contains a lot of bugs and should not be used on any live website.

There are 2 versions available from McDonalds Store (see signature).
WF-Links 1.03B is the original module without the original bugs and an important security fix.
WF-Links 1.03C is a hacked version of v1.03B.

5
jd4x4
Re: WF-Links permissions bug?
  • 2007/10/26 18:44

  • jd4x4

  • Just popping in

  • Posts: 7

  • Since: 2007/10/18


Hi all.. Thanks for the quick replies. I found a solution, but it was a bit of a hack to the template.. would like to see if there's a better way.

I'm using 1.03b from McDonald's site, with XOOPS v 2.0.17.1.

The problem is (was!) that if an anonymous user views the link page, and then clicks on "View Full Details", they can then click the link to the poster, which then gives them a clickable link to any of the poster's entries regardless of their category view permissions.

What I did was edit the wflinks_singlelink.html template to delete the lines 87-94, which displays the list of other posts by submitter.

It would be nice if I had a solution where I didn't have to do that though.

6
McDonald
Re: WF-Links permissions bug?
  • 2007/10/27 23:12

  • McDonald

  • Home away from home

  • Posts: 1072

  • Since: 2005/8/15


With WF-Links it's only possible to give user groups view rights for categories, not for the links themself.
If you want that users are not able to view a link at all you have to set it offline.

There will be an option in the next release of WF-Links 1.03c to turn the 'other links submitted by:' on or off in the preferences.

7
jd4x4
Re: WF-Links permissions bug?
  • 2007/10/29 3:17

  • jd4x4

  • Just popping in

  • Posts: 7

  • Since: 2007/10/18


Thanks for the clarification, McDonald. Subtle but definite difference!!

As I was thinking about it more, being able to turn on/off the ability to see other submitter's links based upon (the viewer's) user level would fit nicely into your current security scheme. I was going to attempt changing your templates/code to do just that, but you'll likely get around to it before I will (and you know what you're doing as well)!

8
McDonald
Re: WF-Links permissions bug?
  • 2007/10/29 7:23

  • McDonald

  • Home away from home

  • Posts: 1072

  • Since: 2005/8/15


Quote:

jd4x4 wrote:
As I was thinking about it more, being able to turn on/off the ability to see other submitter's links based upon (the viewer's) user level would fit nicely into your current security scheme. I was going to attempt changing your templates/code to do just that, but you'll likely get around to it before I will (and you know what you're doing as well)!


Don't make it too difficult for me, I am not a programmer.

There will just be an option in the preferences to turn on/off the links.

But first I have to fix the permissions page because that doesn't work on some server configs.

Login

Who's Online

351 user(s) are online (260 user(s) are browsing Support Forums)


Members: 0


Guests: 351


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Nov 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits