Skip to main content Help Control Panel

YACS CMS : Open source !

Community «   Discussion forum «   Post your requirements here «  

A security Issue.

avatarFragoso, João Leonardo -- on Mar. 12 2004
A brazilian living in France...
A security issue question about modifing/editing published articles.
I have found a simple problem of security. When A member (as I am doing now) post a page in some section without auto_publish, the poste page will wait for webmaestro to be published. This is a good idea to control what is published into the site. However, after the webmaestro have published a member page, the member still has edit/modify rigths on his/her article, so a member can change the published content of a YACS site.

This feature can be suppressed? Can I (as webmaestro) remove edit/modify rights of an article when i publishing it, without changing the article owner?

Thanks.
Bernard
avatar
from nearby-an-airport
Associate, 6927 posts

on Mar. 12 2004


If I am understanding you correctly, this should be a global setting rather than a per-page setting.

Maybe we could extend the scope of the existing parameter controlling content publishing:
  • by default, published pages could not be modified except by some associate
  • in Wiki mode, published pages could be modified by their original poster


Does this make sense to you?
Bernard
avatar
from nearby-an-airport
Associate, 6927 posts

on Feb. 16 2005


Joao: The tonight release of YACS forbids the afterwards modification of published pages, except if allowed through a new global parameter.

Thank you for your input and for your interest into YACS.

 
Share
Information channels
Recent files