Welcome, Guest
Username: Password: Remember me
  • Page:
  • 1

TOPIC:

[FIXED] ACL editOwn and viewOwn 19 Dec 2012 17:14 #6199

I am not able to get the editOwn and viewOwn ACL options to work for registered users in the sandbox. I have set the component options for Registered Users to Allowed for Edit Own, View Own and Delete Own.

When viewing from the front end, I can see ALL the items in the DB, not just the one user's. So the ViewOwn is not being enforced. I am using User: Nina as the owner of one item and User: Admin as the owner of another item. User Nina can see User: Admin's items.

I do NOT see any edit button. There is a check box, but no obvious way to edit the item.

I see the delete button, so that option appears to be working.

Another post sugested I remove and re-add the Created By and Published fields. I tried that with no change.

Am I missing somthing?

Please Log in or Create an account to join the conversation.

Re: ACL editOwn and viewOwn 19 Dec 2012 17:55 #6200

  • JoomGuy
  • JoomGuy's Avatar
  • Offline
  • Moderator
  • Moderator
  • Joomla Enthusiast, Lover of Cooking
  • Posts: 1115
  • Thank you received: 195
Are these items using the publishing wizard?

If they are published (true) then they will always return in public results.

Gez
Need help with your Cook/Joomla Project? . PM me to find out what I can help with. NO time wasters please!!!

Please Log in or Create an account to join the conversation.

Re: ACL editOwn and viewOwn 19 Dec 2012 17:58 #6201

Yes, I am using the publishing wizard. I can find a way to filter the results after I download the component.

The real problem is that the user (Nina) can't edit items for which they are the creator.

Please Log in or Create an account to join the conversation.

Re: ACL editOwn and viewOwn 19 Dec 2012 19:36 #6203

  • JoomGuy
  • JoomGuy's Avatar
  • Offline
  • Moderator
  • Moderator
  • Joomla Enthusiast, Lover of Cooking
  • Posts: 1115
  • Thank you received: 195
Works perfect for me!

So, I've created a frontend form for the user to enter their name - that's all.

Wizards
  1. Author wizard with Created/Edited By and Date fields. Permissions set to allow Registered Create, Edit Own, View Own & Delete own.
  2. Publishing wizard Default set to 0, prefill form (public users cannot override this anyway as they don't have edit state privilege.


The one issue is that, a user can target other users' records by pumping in the cid parameter in the url of the fly view (confirmation) layout I have created also. I guess here, we need to check in the view that the user is the owner too but aside from that, it's working as expected.

As registered user, I can only see my own records in the grid.

Hope it helps!

Gez
Need help with your Cook/Joomla Project? . PM me to find out what I can help with. NO time wasters please!!!

Please Log in or Create an account to join the conversation.

Last edit: by JoomGuy.

Re: ACL editOwn and viewOwn 19 Dec 2012 23:34 #6206

  • admin
  • admin's Avatar
  • Offline
  • Administrator
  • Administrator
  • Chef
  • Posts: 3711
  • Thank you received: 986
Fixed.

There was some ACLs problems still there.

@audibleid : thank you for your eagle eye.
You have noticed a lot of exploits ;-)
Coding is now a piece of cake
The following user(s) said Thank You: rholzler

Please Log in or Create an account to join the conversation.

  • Page:
  • 1
Time to create page: 0.066 seconds

Hi guys Before I ask for help just like to say I tried the tutorials on how to make a 2.5 component WOW.... HECTIC!! J-Cook is really amazing in its simplicity!!
Dorac (Forum)  

Get Started