Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
UBBDev.com
UBBWiki.com
Who's Online Now
2 registered members (Zarzal, isaac), 84 guests, and 223 spiders.
Key: Admin, Global Mod, Mod
Member Spotlight
Bill B
Bill B
Issaquah, WA
Posts: 370
Joined: October 2006
Show All Member Profiles 
Top Posters(30 Days)
isaac 22
Gizmo 17
TheBrit 14
Zarzal 12
SteveS 8
Ruben 4
jorb 4
Latest Photos
Test
Testing to drag photos
Comfortable Cats
Test
BSA photos
Previous Thread
Next Thread
Print Thread
Permissions problem #261847
11/25/18 09:44 PM
11/25/18 09:44 PM
Baldeagle  Offline OP
Enthusiast
Joined: Oct 2007
Posts: 247
On our forum, we have a Moderator Forum that's only visible to Administrators, Global Moderators, and Moderators. Except there's a problem with that. Even as a Guest I can view posts in the Moderator Forum.

I can demonstrate this to you easily. Go to this thread: https://www.stovebolt.com/ubbthreads/ubbthreads.php/topics/1288422/new-addition.html#Post1288422

The Moderator in this thread is Achipmunk. Click on his Display Name, then select Show Forum Posts. From the dropdown list of his posts, select one in the Moderator Forum.

Click on it. You'll be viewing a thread in the Moderator Forum.

Now scroll to the top and click on Moderator Forum in the breadcrumbs.

You'll be taken to a login page and told you don't have permission to see this as a guest.

Click on Previous Page and you'll go right back to the forum you don't have permission to view.

This seems like a loophole in the code. A quick and dirty way to fix it would be to never display posts for a prohibited forum in the Posts list, but that ISTM doesn't really fix the problem.

The real problem is that you should not be allowed to view a post if you don't have permission to view it no matter how you arrived at it. If I send you the link to the post directly, you can view it as a Guest, without having to go through the above steps. So it appears that permissions are not being verified before viewing posts.


The Stovebolt Geek
http://www.stovebolt.com/ubbthreads/ubbthreads.php

UBBThreads 7.6.1.1
Web Server Apache/2.4.29
PHP Version 5.6.32
MySQL Version 5.5.58-log
Database Size 2.04 GB
Express Hosting
Express Hosting "We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
Re: Permissions problem [Re: Baldeagle] #261849
11/25/18 10:35 PM
11/25/18 10:35 PM
Gizmo  Offline
UBB.threads Developer
Joined: Jun 2006
Posts: 17,016
Portland, OR; USA
I am unable to replicate this here at UBBCentral, what do the permissions show for "Can read threads" AND "Can see forum" on the guest user group in that forum?


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Need to Upgrade?
Forums: A Gardeners Forum Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Re: Permissions problem [Re: Baldeagle] #261850
11/26/18 01:21 AM
11/26/18 01:21 AM
isaac  Online Splat
UBB.threads Developer
Joined: Apr 2004
Posts: 1,251
California
As Gizmo wrote,
it looks like in your Moderator forum, you are denying "Can see forum" permissions to guests, while giving them "Can read threads" permission.

Attached screenshot of the correct setting for your desired configuration.

It's probably also a good idea to review the rest of the your [admin/moderator forum title] Forum Permissions while on its page.

Attached Files 20181125_22-18-01.PNG

isaac @ id242.com // my forum @ CelicaHobby.com
a current developer of UBB.threads php forum software // 7.6.2 Released
Re: Permissions problem [Re: Baldeagle] #261851
11/26/18 01:55 PM
11/26/18 01:55 PM
Baldeagle  Offline OP
Enthusiast
Joined: Oct 2007
Posts: 247
Thanks. It looks like a standard template got applied to that forum at some point. I had to correct quite a few permissions in that forum. It's fixed now. Thanks for the pointers.


The Stovebolt Geek
http://www.stovebolt.com/ubbthreads/ubbthreads.php

UBBThreads 7.6.1.1
Web Server Apache/2.4.29
PHP Version 5.6.32
MySQL Version 5.5.58-log
Database Size 2.04 GB

Shout Box
Today's Birthdays
No Birthdays
Recent Topics
Calendar Function
by TheBrit. 12/17/18 10:05 PM
Speaking of Http to https, complaints from user
by PianoWorld. 12/16/18 03:40 PM
update multilanguage site problem
by Zarzal. 12/15/18 04:20 PM
Char coding utf-8 and older forums
by Zarzal. 12/15/18 03:59 PM
table issue
by TheBrit. 12/13/18 06:05 PM
Forum Statistics
Forums36
Topics35,182
Posts191,701
Members12,122
Most Online978
Jun 24th, 2007
Random Image
Powered by UBB.threads™ PHP Forum Software 7.6.2