I've got the latest drupal 6.9 installed with webform. My concern is the permissions. I have setup my content admins to have access to own webform results and to clear webform results. When I log in as one of those users, the permissions don't restrict to only those two things. There appers to be no restrictions at all.
Any ideas here? I think this is a critical issue as it can be a security risk for data.
Thanks in advance for the help.

Comments

cdale’s picture

Status: Active » Postponed (maintainer needs more info)

I wasn't aware that there was an "access own webform results" permission. There's an access own webform submissions perhaps you got that confused?

It is my understanding that access webform results, and clear webform results are an all or nothing kind of thing across all webforms in the system, although I can see the merit in an access own results permission.

Would webform having an access own results, and clear own results permission solve your problem? Or is there more too it that I am not understanding?

What kind of restrictions were you expecting?

quicksketch’s picture

Category: bug » support

That's right, Webform doesn't (yet) have "access own webform results", there's only "access webform results", which will grant access to view the results of all Webforms.

quicksketch’s picture

Priority: Critical » Normal
Status: Postponed (maintainer needs more info) » Fixed

See #246371: Adding new permissions for accessing own webform results and deleting webform submissions for the feature request. Please reopen if this is not what you were expecting.

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.