Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Module Editors can delete modules?Module Editors can delete modules?
Previous
 
Next
New Post
12/1/2010 4:19 PM
 
I'm trying to set up a site (5.6.0) wherein a particular type of user ("Board Member") should be able to edit the content of various modules (Events, for example), but I don't want them to be able to delete modules or change the settings of modules.  These folks know just enough to be dangerous, and I'd really like it if they couldn't mess up the site and have to call me every 10 minutes.

So I created a Calendar page, and set it so that only Administrators have Edit Page access.  I added an Events module, inherited the View permissions, and set the "Board Member" role to have Edit Module access. 

The problem is, when I log in as a test board member, I can delete the module right off the page!  It seems more logical to me that only a Page Editor should be able to do that... Module Editors should be able to change the contents of a module, but not whether it exists or where it is on the page, and holy crap, they can change the security settings (role access and the like) too!  How do I prevent all that while still allowing Board Members to create and moderate events, which seems to require Module Editor status?

I've also tested with a few other modules (Newsletters comes to mind), and the same behavior applies.  This seems like a pretty freakin' huge security hole.
 
New Post
12/1/2010 5:32 PM
 
UPDATE:

I checked my local developer copy, and it behaved as I expected it to.  I compared versions in the Host Settings.  The website version was 05.06.00, while my developer copy was 05.05.01.  I went ahead and upgraded the developer copy to 05.06.00, and suddenly the problem appeared.

Basically, I think the problem is that the Control Panel stuff shows up in the Module Action Menu and it's not supposed to when the user is not a Page Editor.  I don't know if this means that this post belongs in your bug reports instead of Admin/Config, but it seems like it's a pretty darn big bug.
 
New Post
12/1/2010 6:52 PM
 
I can also confirm this issue in a clean install of 5.06.00 vs a clean install of 5.05.01. The user with edit permission on a module instance receives the same module action menu items (settings, import/export, move, delete) as an admin user or user with page edit permissions would receive.

Bill, WESNet Designs
Team Lead - DotNetNuke Gallery Module Project (Not Actively Being Developed)
Extensions Forge Projects . . .
Current: UserExport, ContentDeJour, ePrayer, DNN NewsTicker, By Invitation
Coming Soon: FRBO-For Rent By Owner
 
New Post
12/3/2010 10:47 AM
 
I've posted a solution in the other thread dealing with this issue: http://www.dotnetnuke.com/Resources/Forums/tabid/795/forumid/200/threadid/397993/scope/posts/threadpage/3/Default.aspx
 
New Post
12/3/2010 11:05 AM
 
Tom, please make sure, your solution gets appended to the item in the issue tracker at support.dotnetnuke.com.

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Module Editors can delete modules?Module Editors can delete modules?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out