• 1

Read this first!

We do not monitor these forums. The forum is provided to exchange information and experience with other users ONLY. Forum responses are not guaranteed.

However, please submit a ticket if you have an active subscription and wish to receive support. Our ticketing system is the only way of getting in touch with RSJoomla! and receiving the official RSJoomla! Customer Support.

For more information, the Support Policy is located here.

Thank you!

TOPIC: Help! Locking events to prevent public updating

Help! Locking events to prevent public updating 11 years 1 month ago #22113

  • perini-ps
  • perini-ps's Avatar
  • OFFLINE
  • Fresh Boarder
  • Posts: 18
  • Thank you received: 1
We're using RS Events Pro to build a user-generated calendar. We only use the Public group, so anyone can submit events (although they are moderated prior to publishing).

If I browse the live events, they look like this:

www.acme.com/event/44-event-title

so, as long as I know the ID, I can then change that event's content, by figuring out the URL:

www.acme.com/event/44-new-event

even if that event was not submitted by me - because we are using the Public group.

That is a security nightmare.

What can we do to prevent access to updating that event, after it has been published?

Thanks,
Paul



(btw I have also just submitted this as a ticket)
Last Edit: 11 years 1 month ago by perini-ps.
The administrator has disabled public write access.

Help! Locking events to prevent public updating 11 years 1 month ago #22139

  • perini-ps
  • perini-ps's Avatar
  • OFFLINE
  • Fresh Boarder
  • Posts: 18
  • Thank you received: 1
Done. Thanks to Andrei, I just needed an update to R4, which fixes the problem.
The administrator has disabled public write access.
  • 1

Read this first!

We do not monitor these forums. The forum is provided to exchange information and experience with other users ONLY. Forum responses are not guaranteed.

However, please submit a ticket if you have an active subscription and wish to receive support. Our ticketing system is the only way of getting in touch with RSJoomla! and receiving the official RSJoomla! Customer Support.

For more information, the Support Policy is located here.

Thank you!