3.81 User Accounts
4 posts by 3 authors in: Forums > CMS Builder
Last Post: Yesterday at 8:46pm (RSS)
I just noticed an issue with user permissions on a few 3.81 installs that I have tested specifically for this problem.
- If I set a user to Viewer, they can't see any records.
- If I set them to Viewer & Author, they can't see any other records, but can create them.
- If I set them to Editor or Author, everything works as expected.
Kenny H
By Dave - Yesterday at 2:31pm
Hi Kenny,
Can you check whether "view" access is checked under the database editor for that section? If not, does that resolve it?
Let me know if this worked differently in the past, and we can revert it. Currently, it needs view access on the User Account and the section.
We're working to make it simpler, but let us know if you have any feedback. Thanks!
interactivetools.com
Hi Dave -
That did resolve the issue. I'm not sure how it was before as I rarely check things from this point of view. Most of my websites are locked out from the clients and my CMSB account is the only active account. In the cases where the clients have access, it is very limited (so they don't hurt themselves).
This only came up because I have employees that need access to some of the data in my Development Dashboard, but there is some info I don't want them to see like revenue, API keys, server passwords, etc... HOWEVER, I implemented front-end forms where they can edit limited data and never see the backend of the CMS.
I don't think it's an issue for me. Maybe a note somewhere that "View" must be turned on for a section before you can give someone "View" access. I just realized that I turned off "View" access since they would be able to see sensitive data regardless of being able to edit it. I don't have a case where this affects other websites, so it's all good working the way you have it.
Kenny H
I have used access control quite a bit, when set to view or author, you have quite a bit of fine grained control over what they can view/edit. authorbcan only edit records they created.
yaadev.com