Admin Security
- batmike
- Commander (CMDR)
- Posts: 123
- Joined: Tue Sep 04, 2007 10:46 am
- Location: Minneapolis, MN
- Contact:
Admin Security
I noticed that any admin user can access any admin page is they type in the full URL of whatever page they're trying to access. This doesn't seem to work for all pages (the users page kicked back to the login page) but it does work for the store settings page and the password policy page (the only one's I checked). Is there any way to make sure all pages are secure from direct access even by other admins who don't need to be changing the store settings and things like that.
Thanks,
Mike
Thanks,
Mike
- jmestep
- AbleCommerce Angel
- Posts: 8164
- Joined: Sun Feb 29, 2004 8:04 pm
- Location: Dayton, OH
- Contact:
Re: Admin Security
I think this would be a matter of assigning users to a particular group based on the functions they will be allowed access to.
Judy Estep
Web Developer
jestep@web2market.com
http://www.web2market.com
708-653-3100 x209
New search report plugin for business intelligence:
http://www.web2market.com/Search-Report ... -P154.aspx
Web Developer
jestep@web2market.com
http://www.web2market.com
708-653-3100 x209
New search report plugin for business intelligence:
http://www.web2market.com/Search-Report ... -P154.aspx
- batmike
- Commander (CMDR)
- Posts: 123
- Joined: Tue Sep 04, 2007 10:46 am
- Location: Minneapolis, MN
- Contact:
Re: Admin Security
Thanks for the reply.
I have done that. I tested it from a user that is only allowed access to the catalog and the orders. I then manually typed in the url of the store settings page and it brought it up no problem.
I have done that. I tested it from a user that is only allowed access to the catalog and the orders. I then manually typed in the url of the store settings page and it brought it up no problem.
- jmestep
- AbleCommerce Angel
- Posts: 8164
- Joined: Sun Feb 29, 2004 8:04 pm
- Location: Dayton, OH
- Contact:
Re: Admin Security
I just tested it on a site where I am an admin, not a super user and don't have access to the password policy. You are correct- I was able to access the password policy page by typing in the URL.
I'm going to post a bug.
I'm going to post a bug.
Judy Estep
Web Developer
jestep@web2market.com
http://www.web2market.com
708-653-3100 x209
New search report plugin for business intelligence:
http://www.web2market.com/Search-Report ... -P154.aspx
Web Developer
jestep@web2market.com
http://www.web2market.com
708-653-3100 x209
New search report plugin for business intelligence:
http://www.web2market.com/Search-Report ... -P154.aspx
- batmike
- Commander (CMDR)
- Posts: 123
- Joined: Tue Sep 04, 2007 10:46 am
- Location: Minneapolis, MN
- Contact:
Re: Admin Security
Sounds good, let me know what you find out.
Mike
Mike
- Logan Rhodehamel
- Developer
- Posts: 4116
- Joined: Wed Dec 10, 2003 5:26 pm
Re: Admin Security
Bug 6784. It will be investigated (and solved) today. I have an idea of what the problem is.
Cheers,
Logan
.com
If I do not respond to an unsolicited private message, it's not because I'm ignoring you. It's because the answer to your question is valuable to others. Try the new topic button.
Logan

If I do not respond to an unsolicited private message, it's not because I'm ignoring you. It's because the answer to your question is valuable to others. Try the new topic button.
- Logan Rhodehamel
- Developer
- Posts: 4116
- Joined: Wed Dec 10, 2003 5:26 pm
Re: Admin Security
Cheers,
Logan
.com
If I do not respond to an unsolicited private message, it's not because I'm ignoring you. It's because the answer to your question is valuable to others. Try the new topic button.
Logan

If I do not respond to an unsolicited private message, it's not because I'm ignoring you. It's because the answer to your question is valuable to others. Try the new topic button.
- jmestep
- AbleCommerce Angel
- Posts: 8164
- Joined: Sun Feb 29, 2004 8:04 pm
- Location: Dayton, OH
- Contact:
Re: Admin Security
I tried to add this to the bug, but it wouldn't let me:
Are you sure the new/overwrite instructions are right?
I've looked in two installs and there is no web.config in Admin\Store
But there is a web.config already here:
Admin/Store/Security/Web.config
Are you sure the new/overwrite instructions are right?
I've looked in two installs and there is no web.config in Admin\Store
But there is a web.config already here:
Admin/Store/Security/Web.config
Judy Estep
Web Developer
jestep@web2market.com
http://www.web2market.com
708-653-3100 x209
New search report plugin for business intelligence:
http://www.web2market.com/Search-Report ... -P154.aspx
Web Developer
jestep@web2market.com
http://www.web2market.com
708-653-3100 x209
New search report plugin for business intelligence:
http://www.web2market.com/Search-Report ... -P154.aspx
- Logan Rhodehamel
- Developer
- Posts: 4116
- Joined: Wed Dec 10, 2003 5:26 pm
Re: Admin Security
I reversed them. The store/security file was the one that already exists. The other three files are new. I added a comment on the bug to that effect.
Cheers,
Logan
.com
If I do not respond to an unsolicited private message, it's not because I'm ignoring you. It's because the answer to your question is valuable to others. Try the new topic button.
Logan

If I do not respond to an unsolicited private message, it's not because I'm ignoring you. It's because the answer to your question is valuable to others. Try the new topic button.