YAFLogo

Pau
  • Pau
  • 65% (Friendly)
  • YAF Lover Topic Starter
10 years ago
I've a forum and I want to allow guests to comments...

However, I've noticed that any guest user can delete anothers guests comments...

This seems a very serious issue, don't you think? Or am I doing something wrong?

I am using by YAF 1.9.6 BETA 1 (4b3c9eb7e948)

Sponsor
Pau
  • Pau
  • 65% (Friendly)
  • YAF Lover Topic Starter
10 years ago
A guest user can even edit another people's comments!
Zero2Cool
10 years ago
On the forums individual role permissions, it appears you may have given Guest the role of Admin.

Host > Settings > Forums > Edit (on any forum)

Towards the bottom of the page, you'll see "Edit Forum:"

Under "Group" you'll see "Guests" make sure in the drop down menu on the right, they have "Read Only Access" or "Member Only Access" and not "Admin Access".

Pau
  • Pau
  • 65% (Friendly)
  • YAF Lover Topic Starter
10 years ago
Originally Posted by: Zero2Cool 

On the forums individual role permissions, it appears you may have given Guest the role of Admin.

Host > Settings > Forums > Edit (on any forum)

Towards the bottom of the page, you'll see "Edit Forum:"

Under "Group" you'll see "Guests" make sure in the drop down menu on the right, they have "Read Only Access" or "Member Only Access" and not "Admin Access".

It says "Member Access". Here you can see an screenshot:

UserPostedImage

Zero2Cool
10 years ago
Is the Guest removing other Guests or Members posts? Also, do you have Members role defined to allow deleting of others posts?
Pau
  • Pau
  • 65% (Friendly)
  • YAF Lover Topic Starter
10 years ago
Originally Posted by: Zero2Cool 

Is the Guest removing other Guests or Members posts?

Only other guests posts.

Originally Posted by: Zero2Cool 

Also, do you have Members role defined to

allow deleting of others posts?

I don't understand your question.

I don't see any "Members role". I see "Administrators", "Guests", or "Registered".

Pau
  • Pau
  • 65% (Friendly)
  • YAF Lover Topic Starter
Pau
  • Pau
  • 65% (Friendly)
  • YAF Lover Topic Starter
10 years ago
I think I have founded and fixed the issue.

Right now, I've edited access masks this way:

UserPostedImage

And I've assigned "Read only access" to guest's users.

It works!

Is this the expected way? I think it is not obvious for newbies... I think a guest user shouldnot be able to eliminate posts under ay circunstances...

Zero2Cool
10 years ago
I'm not sure if that's intended. Sorry, I should have said Mask, not Role I think. I've only allowed Guests read access so my experience is limited on that area.
tha_watcha
  • tha_watcha
  • 100% (Exalted)
  • YAF.NET Project Lead 🤴 YAF Version: 3.0.3
10 years ago
Ok here is the problem: if you set the access mask for guest user roles to member, every guest can edit/delete/ create by default, because a guest user is basically in yaf one user. The problem is also here in that forum.

if you want to allow guests to post message but not delete or edit the only solution is to create a new access mask with post allowes and edit and delete, and assaign that mask to the guest role.

Pau
  • Pau
  • 65% (Friendly)
  • YAF Lover Topic Starter
10 years ago
Thanks anyway. You guided me in the right direction. 🙂