CiviCRM Community Forums (archive)

*

News:

Have a question about CiviCRM?
Get it answered quickly at the new
CiviCRM Stack Exchange Q+A site

This forum was archived on 25 November 2017. Learn more.
How to get involved.
What to do if you think you've found a bug.



  • CiviCRM Community Forums (archive) »
  • Old sections (read-only, deprecated) »
  • Support »
  • Installing CiviCRM »
  • Standalone Installations (Moderator: cap10morgan) »
  • APPARENT SECURITY PROBLEM IN 3.0.1 ACTUALLY A CONTACT EDIT LOGIC PROBLEM
Pages: [1]

Author Topic: APPARENT SECURITY PROBLEM IN 3.0.1 ACTUALLY A CONTACT EDIT LOGIC PROBLEM  (Read 1500 times)

Will Brownsberger

  • I post occasionally
  • **
  • Posts: 44
  • Karma: 2
APPARENT SECURITY PROBLEM IN 3.0.1 ACTUALLY A CONTACT EDIT LOGIC PROBLEM
October 10, 2009, 10:48:43 am
Here is a way that you may run into the message :

Sorry. A non-recoverable error has occurred.
You do not have permission to access this page.

There seems to be a bug in the contact edit logic.  

If any administrator edits any other administrator contact (editing the civicrm_contact record, for example by changing the job title on the record) then the other contact will be removed from the administrator group (membership in other groups is not affected).  If they are editing themselves and they are the only administrator, then they cannot fix the problem through the user interface and need to go into phpMyAdmin and edit the civicrm_group_contact table and mark themselves as added to groups 1 and 2 and then truncate the acl_cache table.  All will be well again.

But this suggest some bad logic in the contact update table.

I have not demonstrated this on the demo site because I do not have the necessary permissions, but it definitely happens that way on my standalone site.security logic.

« Last Edit: October 15, 2009, 03:59:05 am by WillBrownsberger »

Pages: [1]
  • CiviCRM Community Forums (archive) »
  • Old sections (read-only, deprecated) »
  • Support »
  • Installing CiviCRM »
  • Standalone Installations (Moderator: cap10morgan) »
  • APPARENT SECURITY PROBLEM IN 3.0.1 ACTUALLY A CONTACT EDIT LOGIC PROBLEM

This forum was archived on 2017-11-26.