Results 1 to 4 of 4

Thread: Access to Documents not controlled by Roles?

  1. #1
    Azarov is offline Junior Member
    Join Date
    May 2008
    Posts
    2

    Question Access to Documents not controlled by Roles?

    Hello!
    Looks like "Documents" section have some problems with ACL
    If an user have access rights "All" to "List" of Documents and have not "View" rights, than in documents list there are links to download documents. User can download any file in spite of the fact that he have not rights to view it.
    Furthermore there is nothing about access rights in code of "/download.php". There is only check if user logged in. If an user knows id of some file, then he can freely download it regardless of his access rights.
    Is it bug or I miss something?

    Checked in Sugar Community Edition Version 5.0.0d (Build 3235)

  2. #2
    franklin_sugar is offline Sugar Team Member
    Join Date
    Jun 2006
    Posts
    157

    Default Re: Access to Documents not controlled by Roles?

    Hi Azarov,

    What value did you choose for "View", "Not Set" or "None"? I guess you used "Not Set". Please change it to "None" and try again. It should work.

    Thanks,
    Franklin

  3. #3
    Azarov is offline Junior Member
    Join Date
    May 2008
    Posts
    2

    Default Re: Access to Documents not controlled by Roles?

    Thanks for reply

    I used "None" and it doesn't work :-(
    Here some screenshots:
    rights setup:

    documents list:


    I found a workaround: just edit layout for documents list in studio and remove file_url from default layout.
    But if an skilful user somehow(don't know how) gets id of file, he can download it by composing url like /download.php?type=documents&id=[fileid] regardless of any access rights

  4. #4
    franklin_sugar is offline Sugar Team Member
    Join Date
    Jun 2006
    Posts
    157

    Default Re: Access to Documents not controlled by Roles?

    Hi Azarov,

    Thanks for providing the images. I can reproduce the problem now. Bug 22280 was filed to track this issue. It will be fixed in the upcoming release.

    Thanks for reporting this issue and sorry for the inconvenience.

    Franklin

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Access Control in SugarCRM5 CE Full
    By dhanukanaveen in forum Help
    Replies: 0
    Last Post: 2007-12-15, 09:31 AM
  2. E-mails, Documents and access control
    By WojKaszycki in forum Developer Help
    Replies: 0
    Last Post: 2007-07-22, 09:11 PM
  3. Documents: restricted access to
    By pfo in forum Feature Requests
    Replies: 3
    Last Post: 2006-04-21, 11:16 AM
  4. Access to Documents through Portal
    By malcolmh in forum Feature Requests
    Replies: 0
    Last Post: 2005-07-16, 09:33 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •