Register   Login
     
  Latest Posts  
Tracking image/file clicks
by spirit on 3/21/2010 8:46 AM
Catcha doesnt seem to work
by chaloum on 3/20/2010 8:16 PM
RE: Recently created articles are not shown in list
by atriage on 3/20/2010 10:15 AM
RE: Recently created articles are not shown in list
by spirit on 3/20/2010 10:08 AM
RE: Introducing the most powerful News Slider for Ventrian News Articles
by jhoelz on 3/19/2010 9:29 PM
Rich Snippets for Review, Ratings etc!
by georgelew on 3/19/2010 7:49 PM
Recently created articles are not shown in list
by atriage on 3/19/2010 11:18 AM
RE: News Articles Tokens
by spirit on 3/19/2010 10:43 AM
Author post count and link in listing.item.html
by mattbunce on 3/19/2010 10:18 AM
RE: News Article Detail and Lightbox
by spirit on 3/19/2010 10:12 AM
  Forums  
Subject: Security bug: Can view articles even if user is not allowed
Prev Next
You are not authorized to post a reply.

Author Messages
Mariette KnapUser is Offline
Gold Membership
Ventrian Master
Ventrian Master
Posts:665


2/02/2006 8:11 AM  

This is serious. Similar to http://www.smcculloch.net/Forums/tabid/118/forumid/4/postid/7350/view/topic/Default.aspx. I have created a module on a page with News Articles and allowed only one role to view the content. If an unauthenticated user goes to: http://www.smallbizserver.net/Default.aspx?tabid=268 he does not see the module but if he goes to one of the documents inside the NewsArticle module like: http://www.smallbizserver.net/Default.aspx?tabid=268 he can see the content. This means that this content is also indexed by search engines and I definately don't want that.

This absolutely unacceptable. I just started to move all my documents to news articles and I sure hope Scott can fix this asap.


Mariëtte Knap
Microsoft MVP
Mariette KnapUser is Offline
Gold Membership
Ventrian Master
Ventrian Master
Posts:665


2/02/2006 11:29 AM  

I just thought of a very simple solution for this problem. In the Subscribtion Tools you have created a module that allows one to show content based on the role the user is in. This would be the perfect solution for me.

On my site I have articles. If the summary would be available to all users and the article itself can be organized in the way the Subscription Tools work I will be very happy. If a user is not a Subscriber he will see the summary but as soon as he clicks on 'Read more' there will be a teaser to become a Member. If a member logs in to the same articles the full content will be shown.

I hope this helps.


Mariëtte Knap
Microsoft MVP
Nick ClementsUser is Offline
Gold Membership
Ventrian Active Member
Ventrian Active Member
Posts:29

2/08/2006 10:11 PM  
I would assume that Scott will be looking to fix this 'bug' as it was certainly working as intended a few versions ago. Then you wouldn't need that workaround.

Regards,
Nick
Scott McCullochUser is Offline
Administrators
Ventrian Master
Ventrian Master
Posts:17204


2/09/2006 4:39 AM  

There will be some changes to the way groups work in news articles (similar to active forums), so you can restrict access to the article, summary, full article by role.


Scott McCulloch
Site Administrator
Mariette KnapUser is Offline
Gold Membership
Ventrian Master
Ventrian Master
Posts:665


2/09/2006 7:48 AM  
Can't wait for it

Mariëtte Knap
Microsoft MVP
Alex ShirleyUser is Offline
Gold Membership
Ventrian Master
Ventrian Master
Posts:275


10/06/2006 4:31 PM  
Any ETA on this?
I'm beginning a new commercial website that will use news articles (hopefully) and this fix will be essential before I can launch.

Many thanks!

Alex

Alex Shirley

Scott McCullochUser is Offline
Administrators
Ventrian Master
Ventrian Master
Posts:17204


10/06/2006 5:20 PM  
Currently, the viewing articles is restricted by:-

* IsSecure set (and the person not being in a role)
* No access permissions to the module (via Module Settings)

There is currently no category based permissions, I'm assuming this is what you need? Mariette uses the IsSecure part of the module to secure articles.

Scott McCulloch
Site Administrator
Mariette KnapUser is Offline
Gold Membership
Ventrian Master
Ventrian Master
Posts:665


10/07/2006 1:02 AM  
Yes, works very well.

Mariëtte Knap
Microsoft MVP
You are not authorized to post a reply.
Forums > Modules > News Articles > Security bug: Can view articles even if user is not allowed



ActiveForums 3.7