[#3201] Not Authorized when editing in backend

12 years 3 months ago - 12 years 3 months ago #189525 by rspack
When trying to edit a member's profile information in backend I receive a popup stating:

Message from webpage:
"Not Authorized"

I am logged in a superuser, and this admin only belongs to this group of superusers. At least all I can see listed shows the admin as a superuser (both in Joomla and CB User manager screens).

I am running Joomla 1.7.3, CB 1.7.1, CB Subs 1.2.2

I was attempting to update a field (text field) and received this message. I also cannot edit any other field as it too results in the same Not Authorized popup message.

Had a post in Advanced, was hoping this posting might get a faster answer being it is in Professional.

I tried earlier to resolve the issue by unpublishing all non-core, non-cb subs plugins and nothing fixed the issue. Seems to be an issue solely with CB Subs as it did not start until cb subs was loaded.

Scott

Please Log in to join the conversation.

12 years 3 months ago - 12 years 3 months ago #189540 by rspack
Replied by rspack on topic Re: Not Authorized when editing in backend
Okay the issue is gone, although I cannot exactly tell you what I did that may have fixed the issue. But here is what I did.

In trying to modify a custom text field in the demo/test user's profile I would always get the not authorized popup message on the backend.

This particular text field I was trying to change was being used and set upon activation and expiration or cancellation of a users subscription. The field is supposed to be set using the integration feature under the CB Subs Plan section. I set it up to set the textfield as "Active" (without the quotes) upon an active subscription and to remove or erase the field upon an expired or non-active subscription. I was using the Active entry of this field as a condition to show the user in the Random User module. I had to have something that changed with the members subscription so non-active users would not be shown in the random module, so this was the purpose of this field.

Ok enough with the explanation of the use of this field and what I did to try and fix the issue with the Not Authorize issue.

I logged into the test account and went to the Edit Profile page. This particular field was located under the User Status tab which had the CB Subs with no conditions (No, Normal CB Settings) on both A & B settings for the cb subs section under the field.

Under the user's edit mode I was able to populate the text field and added in the Active text to the field. I saved it with no issues. This lead me to believe that it must have been an issue with CB subs permissions in the backend when trying to edit a member profile using Super User account. I then changed the CB Subs setting for this field to the following;

A: Yes, CB Subs control detailed field access.
A-1: Selected all the plans I have (3 of them) as this field affects all plans.
A-2: No, profile owner himself is also restricted. wit no selection of plans
A-3: Yes for both choices

I saved it and then retried editing it as a Super User in backend and it allowed me to edit the field, as well as all other fields in users profiles. Not sure why adding this one change affected all the other fields editing ability as well. But I can say that this was the only field I used Detailed selection for CB Subs settings. All other fields were just Yes, CB Subs controls field.

I then moved this field to an Admin only tab to hide it from the user.

Ok hope this helps anyone else experiencing this issue. I am makng the assumption that at least one of the fields must have the CB Subs Moderator setting set to allow editing by moderators. Weird as to why this is so. Any other input on this is appreciated. Maybe I am still missing something.

Please Log in to join the conversation.

12 years 3 months ago - 12 years 3 months ago #189629 by krileon
Replied by krileon on topic Re: Not Authorized when editing in backend
That looks like a bug to me. I've created the below bug ticket for further investigation.

#3201


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

12 years 1 month ago - 12 years 1 month ago #196672 by ndee
Hi,

is there any update on this, has this been fixed? I don't find the Bugtracker ID anywhere.

Joomla 2.5.4, CB 1.8, CB Subs 1.2.2

Thanks.

Greets,
ndee

###################
SPEED UP HELP, read first: Help us help you
###################

Please Log in to join the conversation.

12 years 1 month ago #196737 by krileon
Replied by krileon on topic Re: Not Authorized when editing in backend
It's a CBSubs bug ticket and thus only available to the internal team (CBSubs forge is not public). Currently no progress on this issue as of yet. I've marked it for CBSubs 1.3.0 so Beat can review.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

12 years 2 weeks ago - 12 years 2 weeks ago #198036 by ndee
Hi Kyle,

it took many hours to find out but it seems there is another issue triggering "Not authorized" in backend edit mode.

At least for me this bug is related to CB itself. If you move the params field to a unpublished tab.
Here is the Bugreport:
www.joomlapolis.com/forum/147-potential-bug/198038-not-authorized-error-if-params-field-missing#198038

###################
SPEED UP HELP, read first: Help us help you
###################

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.284 seconds

Facebook Twitter LinkedIn