View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
08703 | Bug reports | Security | public | 2014-02-12 12:46 | 2014-02-16 18:32 |
Reporter | supercosh | Assigned To | DenisChenu | ||
Priority | high | Severity | partial_block | ||
Status | closed | Resolution | fixed | ||
Product Version | 2.05+ | ||||
Fixed in Version | 2.05+ | ||||
Summary | 08703: Permission Model broken | ||||
Description | After updating from 131206 to 140204, all users cannot open their surveys anymore. The listing after the login appears, but when clicking on a survey the message on a white screen appears: "Error No Permission" with a button to go back. All users not havin SuperAdmin, cannot open the surveys, even if all other permissions are set. | ||||
Steps To Reproduce |
The Error appears.
| ||||
Tags | No tags attached. | ||||
Bug heat | 256 | ||||
Complete LimeSurvey version number (& build) | 2.05+ 140204 | ||||
I will donate to the project if issue is resolved | No | ||||
Browser | Chrome | ||||
Database type & version | MySQL, 177 | ||||
Server OS (if known) | CentOS | ||||
Webserver software & version (if known) | Apache fast-cgi | ||||
PHP Version | PHP 5.3.27 | ||||
I found out that the permission model has changed from 2.00 to 2.05, and found, that all permissions need to be set on the survey itself. However I suggest it should be documented somewhere how the model changed, since for the user it is not clear that all permissions should be re-set on the survey-level. The best solution of course would be to set the perms automatically when upgrading. |
|
Hi, Yes, but the owner must have all the rigth on his survey.
What is attented : User have all access to this survey. Carsten : owner_id his an exception of Default right (Like super admin) ? If rigth : can take this one. |
|
Yes, owner should be an exception. |
|
Fix committed to master branch: http://bugs.limesurvey.org/plugin.php?page=Source/view&id=13884 |
|
2.05+ Build 140216 released |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2014-02-12 12:46 | supercosh | New Issue | |
2014-02-12 13:03 | supercosh | Note Added: 28644 | |
2014-02-13 00:05 | c_schmitz | Assigned To | => c_schmitz |
2014-02-13 00:05 | c_schmitz | Status | new => assigned |
2014-02-13 08:30 | DenisChenu | Note Added: 28704 | |
2014-02-13 08:32 | c_schmitz | Note Added: 28705 | |
2014-02-13 08:32 | c_schmitz | Assigned To | c_schmitz => DenisChenu |
2014-02-13 19:00 | DenisChenu | Changeset attached | => LimeSurvey master 5b05a171 |
2014-02-13 19:00 | DenisChenu | Note Added: 28715 | |
2014-02-13 19:00 | DenisChenu | Resolution | open => fixed |
2014-02-13 19:05 | DenisChenu | Status | assigned => resolved |
2014-02-13 19:05 | DenisChenu | Fixed in Version | => 2.05+ |
2014-02-16 18:32 | c_schmitz | Note Added: 28778 | |
2014-02-16 18:32 | c_schmitz | Status | resolved => closed |