Personal tools
You are here: Home Products CMF Questions Roadmap #5: Improve Security
Document Actions

#5: Improve Security

Contents
  1. Motivation
  2. Proposal
by Adam Ullman last modified June 11, 2006 - 00:21
Stop Anonymous users from being able to see pages that should be restricted.
Proposed by
adamu
Proposal type
Architecture
State
being-discussed

Motivation

This was proposed by a user...

From my testing, it appears that an anonymous visitor who knows or figures out the right urls may do the following:
- Access questionnaire_edit_form and then
o Modify questions.
o Reset the questionnaire, deleting all previous submissions.
- View results for the questionnaire at pages such as questionnaire_view_results and html_spreadsheet.
- View questionnaire_edit_properties_form (although changes are not permitted there without authentication).

Proposal

Temporary fix involves customising the effected pages and setting the View security setting to Managers and Owners. "questionnaire_edit_form", "questionnaire_edit", "question_position", "questionnaire_reset", "questionnaire_reset_form", "question_edit_form", "question_edit", "html_spreadsheet", "html_spreadsheet2", "questionnaire_view_results", "spreadsheet", "spreadsheet2", "spreadsheet3", "question_barchart", "respondents_view", "questionnaire_properties_edit", "questionnaire_edit_properties_form", "question_delete", "comments_view".

where can I chanege these settings?

Posted by kfujimoto at January 19, 2006 - 05:34

Adam,

Thank you for your nice Porducts.

Now I need to attach this "Temporary fix" to my plone. But I can't find "questionnaire_edit_form", "questionnaire_edit", ...etc settings.

I checked home of my zope and folder of plone but could not find. Please advice to me.

CMFQuestions is 0.5, zope2.7.4, Plone2.0.5

kazuo

Re: where can I change these settings?

Posted by Adam Ullman at January 20, 2006 - 03:29

These files can be found in the portal_skins/questions directory of your plone root, use the ZMI to navigate there and click on the Customize button to change these files. This will move them to the custom folder where they will become editable.

I have confirmed it

Posted by kfujimoto at January 21, 2006 - 15:41

Adamu,

Thank your comment. I have confirmed your explanation now.

kazuo


For any issues with the web site functionality, please file a ticket.

Please consult the policy on plone.org content if you want your content published on this site.

Servers and hosting by