Posted on: 05/23/05 10:11am
By: Anonymous (Eddy)
Hi there,
Just installed Classifads and all works fine apart from one pretty serious problem.
ANYONE can delete or edit a posting made by ANYONE ELSE. I.e. if ADMIN posts an ad, VISITOR can log-in and change it. Furthermore, someone just visiting the site without an account can also change or delete the ads.
Anyone know of a solution to this problem?
Classifads Problem
Posted on: 05/23/05 03:46pm
By: Anonymous (Eddy)
Just checked and when logged in as anyone, the "Admin Only" block also appears on the left hand side of the page.
Seems that the plugin just isn't checking to see whether users are admin or not, it's just allowing them all the same rights.
I need everyone to be able to post, but only the owners can edit their own ads (or delete them).
Any help much appreciated.
Classifads Problem
Posted on: 05/23/05 04:17pm
By: knuff
Hmmm, not sure about the Ads plugins, but from your second post it seems you have been a little to generous in which groups/acces rights you have been giving to anonymous/normal users.
Maybe it is a good start to list the groups you assigned to both normal and anonymous users.
Best Regards,
Boris
Classifads Problem
Posted on: 05/23/05 04:50pm
By: Dirk
Hmm, I had a quick look at the code and there's a proper permissions check for the Admin menu in place. Are you sure you have the latest version of the plugin?
Having said that, please keep in mind that this plugin is old and not supported any more. The last version is available from the
GPlugs CVS[*1] and anyone willing is free to pick it up and run with it ...
bye, Dirk
Classifads Problem
Posted on: 05/24/05 03:22am
By: Robin
[QUOTE BY= Eddy]I need everyone to be able to post, but only the owners can edit their own ads (or delete them).[/QUOTE]
Then you should try zClassifieds.