Admin Security

For general questions and discussions specific to the AbleCommerce 7.0 Asp.Net product.
Post Reply
User avatar
batmike
Commander (CMDR)
Commander (CMDR)
Posts: 123
Joined: Tue Sep 04, 2007 10:46 am
Location: Minneapolis, MN
Contact:

Admin Security

Post by batmike » Thu May 08, 2008 12:52 pm

I noticed that any admin user can access any admin page is they type in the full URL of whatever page they're trying to access. This doesn't seem to work for all pages (the users page kicked back to the login page) but it does work for the store settings page and the password policy page (the only one's I checked). Is there any way to make sure all pages are secure from direct access even by other admins who don't need to be changing the store settings and things like that.

Thanks,
Mike

User avatar
jmestep
AbleCommerce Angel
Posts: 8164
Joined: Sun Feb 29, 2004 8:04 pm
Location: Dayton, OH
Contact:

Re: Admin Security

Post by jmestep » Thu May 08, 2008 2:11 pm

I think this would be a matter of assigning users to a particular group based on the functions they will be allowed access to.
Judy Estep
Web Developer
jestep@web2market.com
http://www.web2market.com
708-653-3100 x209
New search report plugin for business intelligence:
http://www.web2market.com/Search-Report ... -P154.aspx

User avatar
batmike
Commander (CMDR)
Commander (CMDR)
Posts: 123
Joined: Tue Sep 04, 2007 10:46 am
Location: Minneapolis, MN
Contact:

Re: Admin Security

Post by batmike » Thu May 08, 2008 2:33 pm

Thanks for the reply.

I have done that. I tested it from a user that is only allowed access to the catalog and the orders. I then manually typed in the url of the store settings page and it brought it up no problem.

User avatar
jmestep
AbleCommerce Angel
Posts: 8164
Joined: Sun Feb 29, 2004 8:04 pm
Location: Dayton, OH
Contact:

Re: Admin Security

Post by jmestep » Thu May 08, 2008 4:16 pm

I just tested it on a site where I am an admin, not a super user and don't have access to the password policy. You are correct- I was able to access the password policy page by typing in the URL.
I'm going to post a bug.
Judy Estep
Web Developer
jestep@web2market.com
http://www.web2market.com
708-653-3100 x209
New search report plugin for business intelligence:
http://www.web2market.com/Search-Report ... -P154.aspx

User avatar
batmike
Commander (CMDR)
Commander (CMDR)
Posts: 123
Joined: Tue Sep 04, 2007 10:46 am
Location: Minneapolis, MN
Contact:

Re: Admin Security

Post by batmike » Thu May 08, 2008 8:57 pm

Sounds good, let me know what you find out.

Mike

User avatar
Logan Rhodehamel
Developer
Developer
Posts: 4116
Joined: Wed Dec 10, 2003 5:26 pm

Re: Admin Security

Post by Logan Rhodehamel » Fri May 09, 2008 11:47 am

Bug 6784. It will be investigated (and solved) today. I have an idea of what the problem is.
Cheers,
Logan
Image.com

If I do not respond to an unsolicited private message, it's not because I'm ignoring you. It's because the answer to your question is valuable to others. Try the new topic button.

User avatar
Logan Rhodehamel
Developer
Developer
Posts: 4116
Joined: Wed Dec 10, 2003 5:26 pm

Re: Admin Security

Post by Logan Rhodehamel » Fri May 09, 2008 1:44 pm

http://bugs.ablecommerce.com/show_bug.cgi?id=6784

There is a proposed patch attached to the bug.
Cheers,
Logan
Image.com

If I do not respond to an unsolicited private message, it's not because I'm ignoring you. It's because the answer to your question is valuable to others. Try the new topic button.

User avatar
jmestep
AbleCommerce Angel
Posts: 8164
Joined: Sun Feb 29, 2004 8:04 pm
Location: Dayton, OH
Contact:

Re: Admin Security

Post by jmestep » Fri May 09, 2008 4:38 pm

I tried to add this to the bug, but it wouldn't let me:
Are you sure the new/overwrite instructions are right?
I've looked in two installs and there is no web.config in Admin\Store
But there is a web.config already here:
Admin/Store/Security/Web.config
Judy Estep
Web Developer
jestep@web2market.com
http://www.web2market.com
708-653-3100 x209
New search report plugin for business intelligence:
http://www.web2market.com/Search-Report ... -P154.aspx

User avatar
Logan Rhodehamel
Developer
Developer
Posts: 4116
Joined: Wed Dec 10, 2003 5:26 pm

Re: Admin Security

Post by Logan Rhodehamel » Fri May 09, 2008 5:58 pm

I reversed them. The store/security file was the one that already exists. The other three files are new. I added a comment on the bug to that effect.
Cheers,
Logan
Image.com

If I do not respond to an unsolicited private message, it's not because I'm ignoring you. It's because the answer to your question is valuable to others. Try the new topic button.

Post Reply