Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: Registered users to create albums in categories other than User galleries  (Read 6664 times)

0 Members and 1 Guest are viewing this topic.

pvsujith

  • Coppermine newbie
  • Offline Offline
  • Posts: 1

Hi,
Is there a way to allow registered users to create albums in any of the available categories? By default, albums created by registered users are under User galleries.

I use:
CPG 1.4.2 stand alone installation
OS - RHL 9
Apache 2.0.40
PHP 4.2.2
MySQL 3.23.54

Regards
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: Registered users to create albums in categories other than User galleries
« Reply #1 on: December 09, 2005, 09:51:22 am »

no, regular users can't create albums inside public categories - no hack available.
Logged

janus

  • Coppermine newbie
  • Offline Offline
  • Posts: 5
    • www.u-janusa.com
Re: Registered users to create albums in categories other than User galleries
« Reply #2 on: December 20, 2005, 09:07:00 am »

Hm...
Yesterday I've spend about two hours to investigate this issue and have made the following fix.
Please have a look into attached files.

Unfortunatelly I have not commented the changes, so you should call the diff command.

It seems to run on my server.
« Last Edit: December 20, 2005, 09:13:50 am by janus »
Logged

janus

  • Coppermine newbie
  • Offline Offline
  • Posts: 5
    • www.u-janusa.com
Re: Registered users to create albums in categories other than User galleries
« Reply #3 on: December 26, 2005, 10:01:04 pm »

any feedback?

°-)
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: Registered users to create albums in categories other than User galleries
« Reply #4 on: December 26, 2005, 11:55:01 pm »

yes: I looked into your submission - it just disables all security on gallery core files, making every user an admin who can then edit the whole gallery at will, leaving the gallery just as vulnerable as if you published your admin account on your own home page. Using your hack is not recommended at all, I strongly suggest you remove it from your site asap. Bypassing security by adding user_admin to the check is not all it takes to securely allow users to create public albums. If things were that easy, we would have added it to coppermine's core long ago ;)
Logged

janus

  • Coppermine newbie
  • Offline Offline
  • Posts: 5
    • www.u-janusa.com
Re: Registered users to create albums in categories other than User galleries
« Reply #5 on: December 27, 2005, 12:34:21 pm »

yes: I looked into your submission - it just disables all security on gallery core files, making every user an admin who can then edit the whole gallery at will, leaving the gallery just as vulnerable as if you published your admin account on your own home page. Using your hack is not recommended at all, I strongly suggest you remove it from your site asap. Bypassing security by adding user_admin to the check is not all it takes to securely allow users to create public albums. If things were that easy, we would have added it to coppermine's core long ago ;)
Yes, that's correct. But I thought, I've changed only the ifs/elses, where it deals with album creation only. And exactly in this issue I'd like to give my users admin rights.
Logged
Pages: [1]   Go Up
 

Page created in 0.019 seconds with 19 queries.