Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: switching users user rights several times  (Read 2723 times)

0 Members and 1 Guest are viewing this topic.

dwo

  • Coppermine frequent poster
  • ***
  • Offline Offline
  • Posts: 143
switching users user rights several times
« on: June 14, 2008, 01:39:01 pm »

Hello.

I have several users and one admin.

I want, that from time to time users should be able to upload in admin albums (in other categories).
Therefore, I want to switch them to admin rights, let them upload, then, I want to switch them back to registered rights.

I tested that and it works fine.

Question: Could this cause problems in the database etc. in the long run?

Thank you very much, regards, Dietmar

Logged

Stramm

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: 00
  • Offline Offline
  • Gender: Male
  • Posts: 6006
    • Bettis Wollwelt
Re: switching users user rights several times
« Reply #1 on: June 14, 2008, 02:51:12 pm »

I do not think that this will cause db problems. However you shouldn't give away admin rights to people you fully trust. With admin rights and google everyone can take over your server.
Why not temporarily change album permissions instead? If it's several albums you could create a sql statement list that you just paste into phpmyadmins command box.

dwo

  • Coppermine frequent poster
  • ***
  • Offline Offline
  • Posts: 143
Re: switching users user rights several times
« Reply #2 on: June 14, 2008, 10:03:04 pm »

Thank you very much Stramm   :)

I would give them rights just for the upload process.

Then, I have removed all "admin tags" and some user tags, too. So they get only the direct link to upload.php, so they dont start playing around ;)

Then, I additionally renamed some files in the root folder like admin.php etc.

So, I think, you need much negative energy to do damage. And if you do, we will install one of our backups. Our server backups twice a day.


But, I will have a look at what you proposed, although I dont quite understood 100% ;)

Best regards, Dietmar

Logged
Pages: [1]   Go Up
 

Page created in 0.017 seconds with 15 queries.