Using DNN 5, I've set up some security roles (EDITOR and TRAINEE).
EDITORs should be able to edit the content of modules (for a module on a page viewable to both roles, I've given edit rights to EDITOR - in the settings window, I have put a green tick against EDITOR in the Edit Module column - I've grabbed a screen shot but can't work out how to get it into this post).
TRAINEES should only be able to view the page (in the Edit Module column, there is no tick against that role). However, in practice, TRAINEE can see the pencil icon on the module and can edit the content!
Is this a bug, or should I be doing something else to restrict edit rights? In addition to specifying who CAN edit module content, do I also have to specify who CAN'T edit module content (by putting the x against the security role)?
I had assumed that by not giving a security role a tick in the edit module column, they wouldn't be able to edit the module. To go through the site now adding crosses will take some time. Also, more than once, I've managed to lock myself out by adding crosses!
Thanks