Site Links
Home
Features
Pricing & Order
Documentation
Support Options
Member Area
UBBDev.com
UBBWiki.com
Who's Online Now
0 registered members (), 67 guests, and 185 spiders.
Key: Admin, Global Mod, Mod
Member Spotlight
Crasher
Crasher
Midlands, UK
Posts: 137
Joined: July 2005
Show All Member Profiles 
Top Posters(30 Days)
isaac 14
Ruben 12
Gizmo 11
Morgan 2
Latest Photos
Trees
Retreats
Rooms
Big stuff
Test
Previous Thread
Next Thread
Print Thread
Permissions problem #261847 11/25/18 10:44 PM
Joined: Oct 2007
Posts: 249
Baldeagle Offline OP
Enthusiast
OP Offline
Enthusiast
Joined: Oct 2007
Posts: 249
On our forum, we have a Moderator Forum that's only visible to Administrators, Global Moderators, and Moderators. Except there's a problem with that. Even as a Guest I can view posts in the Moderator Forum.

I can demonstrate this to you easily. Go to this thread: https://www.stovebolt.com/ubbthreads/ubbthreads.php/topics/1288422/new-addition.html#Post1288422

The Moderator in this thread is Achipmunk. Click on his Display Name, then select Show Forum Posts. From the dropdown list of his posts, select one in the Moderator Forum.

Click on it. You'll be viewing a thread in the Moderator Forum.

Now scroll to the top and click on Moderator Forum in the breadcrumbs.

You'll be taken to a login page and told you don't have permission to see this as a guest.

Click on Previous Page and you'll go right back to the forum you don't have permission to view.

This seems like a loophole in the code. A quick and dirty way to fix it would be to never display posts for a prohibited forum in the Posts list, but that ISTM doesn't really fix the problem.

The real problem is that you should not be allowed to view a post if you don't have permission to view it no matter how you arrived at it. If I send you the link to the post directly, you can view it as a Guest, without having to go through the above steps. So it appears that permissions are not being verified before viewing posts.


The Stovebolt Geek
http://www.stovebolt.com/ubbthreads/ubbthreads.php

UBBThreads 7.6.1.1
Web Server Apache/2.4.35
PHP Version 5.6.38
MySQL Version 5.5.61-log
Database Size 2.16 GB
Express Hosting
Re: Permissions problem [Re: Baldeagle] #261849 11/25/18 11:35 PM
Joined: Jun 2006
Posts: 15,827
Gizmo Offline
UBB.threads Developer
Offline
UBB.threads Developer
Joined: Jun 2006
Posts: 15,827
I am unable to replicate this here at UBBCentral, what do the permissions show for "Can read threads" AND "Can see forum" on the guest user group in that forum?


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Need to Upgrade?
Forums: A Gardeners Forum Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Re: Permissions problem [Re: Baldeagle] #261850 11/26/18 02:21 AM
Joined: Apr 2004
Posts: 1,377
isaac Offline
UBB.threads Developer
Offline
UBB.threads Developer
Joined: Apr 2004
Posts: 1,377
As Gizmo wrote,
it looks like in your Moderator forum, you are denying "Can see forum" permissions to guests, while giving them "Can read threads" permission.

Attached screenshot of the correct setting for your desired configuration.

It's probably also a good idea to review the rest of the your [admin/moderator forum title] Forum Permissions while on its page.

Attached Files 20181125_22-18-01.PNG

isaac @ id242.com // my forum @ CelicaHobby.com
a current developer of UBB.threads php forum software // 7.7.2 Progress Notes
Re: Permissions problem [Re: Baldeagle] #261851 11/26/18 02:55 PM
Joined: Oct 2007
Posts: 249
Baldeagle Offline OP
Enthusiast
OP Offline
Enthusiast
Joined: Oct 2007
Posts: 249
Thanks. It looks like a standard template got applied to that forum at some point. I had to correct quite a few permissions in that forum. It's fixed now. Thanks for the pointers.


The Stovebolt Geek
http://www.stovebolt.com/ubbthreads/ubbthreads.php

UBBThreads 7.6.1.1
Web Server Apache/2.4.35
PHP Version 5.6.38
MySQL Version 5.5.61-log
Database Size 2.16 GB

ShoutChat Box
Today's Birthdays
No Birthdays
Recent Topics
7.7.1 /libs/triggers.inc.p
hp

by BlackMale - 05/24/19 01:52 PM
7.7.1 \admin\do_subchange.
php

by BlackMale - 05/24/19 02:47 AM
7.7.1 scripts/inline_moder
ation.inc.php

by BlackMale - 05/23/19 12:23 AM
7.7.1 forgotten? //$reply = "off";
by BlackMale - 05/13/19 07:25 PM
[FIXED for 7.7.2] 7.7.1 /admin/edit_subscrip
tion.php

by BlackMale - 05/11/19 08:35 AM
Forum Statistics
Forums35
Topics35,295
Posts192,457
Members12,167
Most Online978
Jun 24th, 2007
Random Image
Powered by UBB.threads™ PHP Forum Software 7.7.2
(Snapshot build 20190501)