Page 1 of 1

6.2.2 Folder Security flaw

PostPosted:Wed Jan 23, 2013 11:34 am
by thecjman
Hi
I am on 6.2.2 zip install on ubuntu and all is working BUT NOT THE folder security
All users with ROLE_ADMIN can see all folders under okm:personal
BUT users with ANY other roles can ONLY see their own personal folder.
  • U can not add the ROLE_USER to any folder from the UI so I added it from the DB side to the okm:personal folder and to a sub folder, I then can see the permissions from the UI and change them etc with the okmAdmin user logged on but if the standard user with ONLY ROLE_USER log on then - No luck
  • I then ALSO added the user to okm:personal and subfolder with full permissions - BUT No luck
  • I added a ROLE_PowerUser to the system and added this ROLE_PowerUser to the user, okm:personal and subfolder - BUT No luck
Any other Ideas

Re: 6.2.2 Folder Security flaw

PostPosted:Thu Jan 24, 2013 11:21 am
by thecjman
I think I have successfully solved my problem BUT it should (I think) be classed as a bug.
If the ROLE_ADMIN is not assigned and you have any other ROLES like ROLE_USER then you need to make sure the PROFILE has ONLY Stack PERSONAL and TRASH ticked, if you tick any other STACK then you will experience this mentioned problem.

I understand that the "STACK" tick should not have a play in the Access of folders and that the ROLES should be the deciding factor but this is my findings and they are true.

Re: 6.2.2 Folder Security flaw

PostPosted:Fri Jan 25, 2013 5:36 pm
by jllort
This is a duplicated post, if there's some new question on it, please continue with the other. This post can be deleted.

Re: 6.2.2 Folder Security flaw

PostPosted:Tue Jan 29, 2013 10:31 am
by thecjman
This is the URL top the other post: http://forum.openkm.com/viewtopic.php?f=4&t=9202