Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security problem CMS subsite view #446

Open
intwebg opened this issue Oct 31, 2019 · 4 comments
Open

Security problem CMS subsite view #446

intwebg opened this issue Oct 31, 2019 · 4 comments

Comments

@intwebg
Copy link

intwebg commented Oct 31, 2019

A member can access and see all the contents of all subsites if he knows the domain names that are configured in the CMS. He can't change any information but he can see all configurations, text, draft pages. (view only)

A related problem : If a member with a defined subsite connect throught the main site domain, he will see the content of the main site in view only.

@intwebg intwebg changed the title Group access to just one subsite show wrong subsite Security problem CMS subsite view Nov 4, 2019
@brynwhyman
Copy link

I think this is a duplicate of the bug report here, quoting a slightly different scenario: #434

It's clearly a bug with Subsites, but this is a limitation that is not a regression (nor clearly defined in the module documentation).

@intwebg
Copy link
Author

intwebg commented Nov 7, 2019

Looks like the other but I can't confirm totaly because I don't know very well this module. I have another observation. If I uncheck «Access to 'Pages' section» for the group I have created with the user and login with user informations, I'm redirecting directly to the subsite I have selected into the permissions. Now I can't see nothing from other subsites. And when I try to change subsite from the address bar «?SubsiteID=2», I can't access to. So now it works partially because I can't see the site tree to create/modify/delete pages.

@dawb
Copy link

dawb commented Jan 20, 2022

Checking for any progress on this? It is a major limitation of the module that the security permissions don't work correctly. Also it isn't possible to restrict access of users to only the main website, when you don't select a sub site for them to access it removes the dropdown from the admin panel but they can log into any of the other admin area via the domains.

@yvuyvu
Copy link

yvuyvu commented Sep 13, 2023

Any update about this problem? I think it should really not be possible to log in to CMS via other subsites.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants