- Posts: 1
- Thank you received: 0
All questions about EDocman extension
Security issue with document search and view
- Jérome DUCHEMIN
- Topic Author
- Offline
- New Member
Less
More
12 years 4 months ago #18011
by Jérome DUCHEMIN
Security issue with document search and view was created by Jérome DUCHEMIN
There is a problem with document search in eDocman 1.1.0.
I create a category (category4usergroup1) with an access level limited to one user group (usergroup1).
I upload a document in "category4usergroup1" but I don't change the default access level set in the form.
If I do a search with a user that is not a member of "usergroup1", I can find the document in the search results. That's a wrong answer.
The search don't check the parent category of the document to calculate the access rights.
The document consultation reproduces the same problem. The access level of parent category is not verified.
I create a category (category4usergroup1) with an access level limited to one user group (usergroup1).
I upload a document in "category4usergroup1" but I don't change the default access level set in the form.
If I do a search with a user that is not a member of "usergroup1", I can find the document in the search results. That's a wrong answer.
The search don't check the parent category of the document to calculate the access rights.
The document consultation reproduces the same problem. The access level of parent category is not verified.
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
12 years 4 months ago #18012
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Re: Security issue with document search and view
Hi
At the moment, the extension doesn't checking category access when perform searching documents via search function. I can add code to check categories access level as well but it will causes the performance problem.
So the solution is that you set access level for individual document when add/edit document. Could you please do that ?
Tuan
At the moment, the extension doesn't checking category access when perform searching documents via search function. I can add code to check categories access level as well but it will causes the performance problem.
So the solution is that you set access level for individual document when add/edit document. Could you please do that ?
Tuan
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
12 years 4 months ago #18014
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Re: Security issue with document search and view
If you don't want to change access property for each document, you can get the file below, unzip it and upload to components/com_edocman/models folder. After that, when users search for documents, they can only see the documents belong to categories which they have access permission .
Regards,
Tuan
Regards,
Tuan
Please Log in or Create an account to join the conversation.
Moderators: Mr. Dam
Support
Documentation
Information
Copyright © 2024 Joomla Extensions by Joomdonation. All Rights Reserved.
joomdonation.com is not affiliated with or endorsed by the Joomla! Project or Open Source Matters.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.