TP-Docs
HTML5 Icon HTML5 Icon HTML5 Icon
TP on Social Media

Recent

Welcome to TinyPortal. Please login or sign up.

Members
  • Total Members: 3,963
  • Latest: BiZaJe
Stats
  • Total Posts: 195,917
  • Total Topics: 21,308
  • Online today: 884
  • Online ever: 8,223 (February 19, 2025, 04:35:35 AM)
Users Online
  • Users: 0
  • Guests: 458
  • Total: 458

[bugtracker] Admin functions delegated to non-admins don't work

Started by julian7, February 19, 2009, 04:32:43 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

julian7

Nearly all functions in tpadmin action fail on POST, when accessed by a non-administrator user.  For example, article management works for normal users (who got access to article management and tinyportal article functionalities), until the actual newarticle or edit article's POST form submission.

Of course it fails because no subaction is set (in GET variable), which is the base of the security check.  It defaults to tp-news, but if I give permission to news, I'll give permission for everything.

Renegd98

Confirmed,
I gave a test account permissions to manage articles. The link to manage articles works. I can create an article, but when i push save I get the error you see in the attached pic.
No errors are thrown in the error log.

bloc

- TP assumed tp_news permission on non-admins, causing saving to fail. Fixed for v1.0 beta 4

This website is proudly hosted on Crocweb Cloud Website Hosting.