Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: [Solved]: Users with multiple group identities  (Read 2846 times)

0 Members and 1 Guest are viewing this topic.

louisli

  • Coppermine newbie
  • Offline Offline
  • Posts: 12
[Solved]: Users with multiple group identities
« on: July 14, 2008, 04:53:50 pm »

I have an album which is open to "registered" users only becaused I wanted all registered members to see.

I have the "registered" group with permissions:
- Ratings: yes
- e-cards: yes
- Comments: yes

And a "p-friends" group with permission:
- Ratings: yes
- e-cards: no
- Comments: yes

I have made a test account "testuser", I don't want this group of users to send e-cards, while I want them to read the album mentioned above
I have changed his primary group to "p-friends" and secondary group to "registered".  After this user logged in, he can still send e-cards, I tried to swap his primary and secondary groups but this still appears happens.

What should I do so this user is not able to send e-cards?

(CPG 1.4.18 with modpack from SF.net page)

Thanks.

Louis
« Last Edit: July 14, 2008, 06:57:42 pm by Joachim Müller »
Logged
QNAP TS-109 pro NAS box
Apache 1.3.28
PHP 5.2.0
MySQL 5.0.27
CPG 1.4.18

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: Users with multiple group identities
« Reply #1 on: July 14, 2008, 05:29:21 pm »

Members of additional (user defined) groups are still members of the built-in registered group. Members of the user-defined group "p-friends" are therefor members of the standard group "registered" as well. The least restrictive set of permissions apply, so members of the group "p-friends" can send ecards. There is no way to circumvent the fact that members of custom groups are member of the original group "registered" as well (and it would not make any sense btw.). Your permissions should be set from restrictive for the default and non-restrictive for advanced users you know and trust.
Make this the other way round: set permissions for the registered group not to be allowed to send ecards. Create a custom group that is allowed to send ecards and promote your privileged users to be members of that group as well.
Logged

louisli

  • Coppermine newbie
  • Offline Offline
  • Posts: 12
Re: Users with multiple group identities
« Reply #2 on: July 14, 2008, 06:14:42 pm »

ic, it works now, thank you ;D
Logged
QNAP TS-109 pro NAS box
Apache 1.3.28
PHP 5.2.0
MySQL 5.0.27
CPG 1.4.18
Pages: [1]   Go Up
 

Page created in 0.044 seconds with 19 queries.