groupjive security issue not resolved

12 years 7 months ago - 12 years 7 months ago #177332 by inscores
Replied by inscores on topic Re: Potential GJ security risks
so if i install GJ 2.3 will that mean that group members can join but not delete, publish etc? i need for them to join but not have access to those parameters. so, with that said will that version take care of that problem? I had 2.3 installed earlier and that did not fix that issue and on an earlier post you said that guy needed to go to the gj 2.4cr2 so thats what i did. i paid for the upgrade to professional so id have that feature. now your telling me to go backwards?

Please Log in to join the conversation.

12 years 7 months ago - 12 years 7 months ago #177335 by krileon
Replied by krileon on topic Re: Potential GJ security risks

so if i install GJ 2.3 will that mean that group members can join but not delete, publish etc?

They can only see the links to do those actions, but they do not function. Users can only edit/delete their own groups or categories. They can not edit/delete groups or categories they do not own. Site moderators are exempt from this and can do whatever they want.

i need for them to join but not have access to those parameters. so, with that said will that version take care of that problem?

Yes, it's a cosmetic bug affecting GJ 2.4 RC2 only. It should actually work fine in GJ 2.4 RC1 if I recall correctly.

I had 2.3 installed earlier and that did not fix that issue and on an earlier post you said that guy needed to go to the gj 2.4cr2 so thats what i did. i paid for the upgrade to professional so id have that feature. now your telling me to go backwards?

There was no such bug ever reported for GJ 2.3.

GJ 2.4 RC2 introduced this bug with some internal API changes and improvements. I was passing the wrong user object to the authorize function which resulted in links displaying that should not have (again, they don't function without permissions though).

If you could please provide the URL where you were under the impress you needed 2.4 would be appreciated.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

12 years 7 months ago #177343 by inscores
Replied by inscores on topic Re: Potential GJ security risks
here is the thread link! so, again it did not work in 2.3 either. i am not a computer joomla beginner so i tried all possible ways. yes, outsiders un-registered could not delete etc. in both versions. in the 2.4 version same thing but also once registered owner or NOn owner could delete etc. trust me i tried all ways.

www.joomlapolis.com/forum/154-advanced-members-support/175373-solved-group-jive-user-creation-of-groups--group-acces#175373



This feature is added with next release (GJ 2.4). Currently GJ 2.4rc1 is available to professional subscribers with GJ 2.4rc2 to soon release to professional subscribers. Once out of testing to be moved to advanced and professional subscribers as GJ 2.4 stable. With next release for nearly all configuration (integrations included) you can select the default value as well as whether that parameter is "visible" or not.

Please Log in to join the conversation.

12 years 7 months ago - 12 years 7 months ago #177402 by krileon
Replied by krileon on topic Re: Potential GJ security risks

here is the thread link! so, again it did not work in 2.3 either. i am not a computer joomla beginner so i tried all possible ways. yes, outsiders un-registered could not delete etc. in both versions. in the 2.4 version same thing but also once registered owner or NOn owner could delete etc. trust me i tried all ways.

www.joomlapolis.com/forum/154-advanced-m...--group-acces#175373

This feature has absolutely nothing to do with your issue. This feature allows changing the parameters seen when editing a group to a different default value or hiding them entirely. Please avoid assumptions when making financial decisions. Again, this issue has never been reported and if is happening on 2.3 and 2.4 then it's likely an ACL issue on your install.

Please provide Joomla and CB version. If on J1.6/J1.7, did you change the default usergroups or accesslevels? You should never alter the defaults and CB is expecting them to exist.

As I can not duplicate on any of my installs please PM backend super administrator login credentials so may investigate possible causes.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

12 years 7 months ago #177444 by inscores
Replied by inscores on topic Re: Potential GJ security risks
Dont be rude! I gave you the joomla version etc in the start of this post! Where does it say i have to keep repeating myself in the same thread? I am not assuming anything. I just freaking needed it to be secure! it is not! registered members can delete groups and each other! thats something i cant have. Furthermore, like i said earlier i tried everything. i am not an idiot! Yes i know not to freaking mess with certain things in joomla period. Been using joomla for years now as a developer. So get off your high horse and quit skirting around this issue. you go back and forth with 2.3 and 2.4. Again, group members can delete each other and that should have been a fix from the get go! I am now using jomsocial and WOW it does not let members delete each other. So it had nothing to do with my install! GIVE ME MY MONEY BACK PERIOD. I will go ahead and contact my bank and paypal for a dispute chargeback. I am not playing. You and Nant have been nothing but rude from the go. Even on other threads you both are rude and talk down to other members. People will start talking on the forums about that so dont hang yourself.I paid for something that simply doesnt work. :woohoo: Thats my final word.

Please Log in to join the conversation.

12 years 7 months ago #177445 by krileon
Replied by krileon on topic Re: Potential GJ security risks
I apologize my intention was absolutely not to be rude by any means. It's simply my personality am afraid. Am a very blunt and forward person :P

I'm sorry you did indeed post as I requested on the first page and did not check before replying. I reply to many many threads each day sometimes the "shortcuts" cause repeat of information.

Within groups Site Moderators, Group Owners, and Category Owners can remove users from groups. Group Owners can of course only remove users from their groups only. Category owners can remove users or edit groups in anyway that below to their category. Site moderators have no limitations. I'm not sure if this is what you were experiencing or not as needed details (step by step, maybe screenshots?) of what was happening.

There is indeed a bug in GJ 2.4 (not known to 2.3) that cause links such as edit and delete to show in the Panel and on profile tabs of GJ, but they were purely cosmetic (unless the user had actual permission to use them of course).

I also requested backend credentials with my previous reply so I could gladly see what could be causing so much trouble. I have also an internal built with numerous bugs fixed (to be next release) am prepared to provide, install, and configure for you to see if we can get this issue squashed.

I assure you our intentions were never to be rude to you and we absolutely respect and value your every feedback.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.248 seconds

Facebook Twitter LinkedIn