Welcome to Squishdot Websites Squishdot How-To Newbies
 about
 search
 post article
 Documentation
 Mailing Lists
 Bug Tracking
 Development
 Installation
 Upgrading
 Download
 admin
 rdf

 main


Anonymous Users have too much Permission
How-To Posted by Mark Matthews on Wednesday July 14, 10:15AM, 2004
from the whats-going-on-dudes dept.
We need Anonymous users to be able to browse the site only, and Authenticated user to be able to post articles and replies as well.
BUT it's not working.

I have set the two sets of secuity settings as specified in page

http://squishdot.org/Documentation/Security.html

on the root folder of Zope (ZMI)- The basic "read-only" set for Anonymous, and the extra "Add Posting" property for AUthenticated users.

However, Anonymous users can still Post and Article, but not a Reply.

What is wrong with my settings?

<  |  >

 

Related Links
  • Articles on How-To
  • Also by Mark Matthews
  • Contact author
  • The Fine Print: The following comments are owned by whoever posted them.
    ( Reply )

    Over 10 comments listed. Printing out index only.
    Re: Anonymous Users have too much Permission
    by Chris Withers on Thursday July 15, 09:49PM, 2004
    Check the security settings on the Squishdot Site object as well...
    [ Reply to this ]
    Re: Anonymous Users have too much Permission
    by Mark Matthews on Monday July 19, 11:55AM, 2004
    I have made the security settings on on both the "root" ZMI object and the Root\MySquishdotSite objects the same;
    Note that i have all the "Acquire permission settings? " = True in the Root\MySquishdotSite folder.

  • Access contents information =True ( Anonymous Authenticated Manager Owner )
  • Add Postings = False (Anonymous )
  • Add Postings = True (Authenticated Manager Owner )
  • Query TinyTable Data = True ( Anonymous Authenticated Manager Owner )
  • View = True ( Anonymous Authenticated Manager Owner )

  • and it still does not work, i.e. Zope/the site still incorrectly allows Anoymous users to Post a new article, but not to Reply, and it should not allow either.
    [ Reply to this ]

     
    The Fine Print: The following comments are owned by whoever posted them.
    ( Reply )

    Powered by Zope  Squishdot Powered
      "Any system that depends on reliability is unreliable." -- Nogg's Postulate
    All trademarks and copyrights on this page are owned by their respective companies. Comments are owned by the Poster. The Rest ©1999 Butch Landingin, ©2000-2002 Chris Withers.