Closed (outdated)
Project:
Content Access
Version:
7.x-1.x-dev
Component:
Miscellaneous
Priority:
Normal
Category:
Support request
Assigned:
Unassigned
Issue tags:
Reporter:
Created:
16 Apr 2011 at 22:30 UTC
Updated:
24 May 2020 at 14:50 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #1
GalainHH commentedThat was my first thought too.
I don´t know what "other" access control module I have installed, but after I set the "Give content node grants priority " to 9, it works
Comment #2
choy commentedcan confirm this behaviour - during my error research i put it first as usual from 0 to -10 to set "high" priority like in usuali in some other drupal module weights - after trying it the other way from 0 to 10 all worked fine …
Comment #3
jdelaune commentednvm working now :)
Comment #4
salvisInstall Devel Node Access to get insight into what's happening on your site.
Comment #5
particlegirl commentedHi I'm having the same issue. Could you please explain how I "Give content node grants priority " to 9?
Many thanks
Comment #6
salvisLook for a fieldset labelled "Advanced."
Comment #7
particlegirl commentedthank you very much, I finally found it under Content Types --> Basic Page --> Manage Fields --> Access Control --> Advanced (for any other noobs stuck on this!)
Comment #8
salvisYou're welcome — be sure to install Devel Node Access and to study and fully understand what you're doing.
Comment #9
gjones commentedI ended up just tossing some logic into my tpl.php files instead.
Comment #10
Todd Young commentedThere is some weirdness in the latest D7 Content Access.
I understood the standard warning "Note that users need at least the access content permission to be able to deal in any way with content" better in D6, but in D7 I can't seem to find that same wording. There's "Grant Content Access" which I'm sure you don't want to enable, and there are various access permissions per node, and then there is "View Published Content" which I enabled. Without that, users could see nothing, but with it they can see everything. I bumped the priority on the "Give content node grants priority" higher but it didn't seem to have an effect.
I can't seem to coalesce all the settings, help docs and forum tips into a solution for the latest D7. Even if I'm missing something and it's working as designed, it's very counter-intuitive. Help!
Comment #11
Todd Young commentedI bumped up the grants priority and triple-checked all settings, confirmed same against Devel, and I'm running no other access modules. I'm pretty sure the current D7 dev version of CA is not working.
Comment #12
Todd Young commentedComment #13
Todd Young commentedOK so I found the error message about 'legacy' nodes and so I had to manually edit and save EVERY node that was created prior to enabling the module. Only then would 'rebuild permissions' disable access according to the CA settings. That is a huge PITA, there should definitely be some way of adopting the nodes automatically. Requiring a hand edit of each is nearly impossible in some cases...
Comment #14
samedgecombe commentedI'm having the same problem as you Todd. Do you mind explaining exactly what you did please?
Cheers
Sam
Comment #15
Crusher commentedHi,
i haven't any problems with CA for D7 right now. It works from 7.0 - 7.2.
What about MySQL? I installed D7.2 on a new Hoster and when i tried to add a custom field, it was saved to SQL, but selection list was still empty.
I had to change MySQL Version from 5.1 to 5.0. Well, in my case it's an hosting error. In xampp D7 works great with MySQL 5.0.
So could it be, that in your case is isn't an CA error? Have you tried some other d7 features? Is everything working fine or is maybe something wrong with MySQL?
greetz Crusher
Comment #16
Todd Young commented@samedgecombe - it seemed I tried everything when I finally gave in and went into "edit" mode of one node, changed nothing, but re-saved it. Things started working properly after that.
I'm not sure if you would have to go into each node or not to accomplish the same effect across all nodes - I only had a couple in at the time, and of differing types.
Comment #17
salvisDon't trust weird behavior, especially not if you need to keep something private.
See #8 above.
Comment #18
samedgecombe commentedI tried that but still no joy :(
Comment #19
samedgecombe commentedCould be a mysql error. The content access table is empty despite my rebuilding permissions and editing and then re-editing the content type that I want to hide. How do I downgrade my mysql type?
Comment #20
samedgecombe commentedI think I fixed it. I had a look at the node_access table using a mysql frontend. There was a line that gave viewing access to all users, otherwise the table was pretty empty. Because I was migrating from another database on the same server, I just dumped the old node_access and imported it the the new table and now everything seems to be working fine.
Comment #21
salvisWhat you're doing is a crime. It'll come back to haunt you.
Comment #22
Crusher commentedHi,
well i said it could be a sql error. You shouldn't delete any entries, until you know what ur dowing.
grant_view = 1
Boolean indicating whether a user with the realm/grant pair can view this node.
So that's ok. You can set it to "1" for normal and restricted nodes. Because realm/grant pair makes the diffrences.
Of course CA settings a stored in sql. So there must be one (or more) entry for each node. More entries?
gid = 2 for example is "authenticated users". So that one is really very mighty. All other Roles (e.g. Administrators, Members,...) aren't necessary.
If you don't enalbe "authenticarted users" role all gid will be listed in seperate line:
nid gid real grant_view grant_update grant_delete
2 3 content_access_rid 1 0 0
2 4 content_access_rid 1 0 0
(nid=2, roles: administrator (3), members (4))
Perhaps you have an error in your db. But deleting entries is very dangerous.
Try to re-install Content Access and make your settings manually. Is everyting working?
Well changing MySQL version could be very tricky! Very good hosters have an management console, where you can change mysql version.
You can't change MySQL on the fly. You must preserve multiple mysql servers. One or more for each version. So your hosters will gave you another mysql server hostname, etc. !
First i would try everything in a testing env. like xampp! Pro: you have the same env. as thousands of people and can easily compare your results with other users.
I have tested CA with xampp v1.7.4 (PHP: 5.3.5 / MySQL 5.5.8).
greetz Crusher
Comment #23
salvisNo, don't ever delete (or add/change) any entries!!! If you know what you're doing, you'll never do that. Stop suggesting that!
The {node_access} table is only temporary storage to optimize page construction time. It makes absolutely no sense to edit the content of that table. Clicking [Rebuild permissions] on admin/content/node-settings will wipe and reconstruct the table's content.
When you install/remove/update a node access module, you may have to do that. Also, if you've mucked with the table, you should do that.
If the result of [Rebuild permissions] is not what you expect, then one of your node access modules may be at fault and need to be fixed, or you may be using it incorrectly. Devel Node Access (enable its Debug mode and the second block) will help you to understand what's going on.
Comment #24
iztok commentedI have the same problems with per-node-type access permissions.
I set the weight to 9, but Devel info still shows that Anonymous user have permissions for viewing the content, permissen given by node_access.
Any idea?
Comment #25
salvisPost a screenshot of both DNA blocks, hovering your mouse over the "permissen given by node_access."
Comment #26
causalloop commentedAttached mine (hi btw).
Its weird, I noticed that even though I can't seem to deny someone access, I can grant them edit access using CA. Changing the priority changed nothing for me. Neither did re-saving nodes. And I'm not going to go mucking about in the sql DB unless I have to. I reserve that for days when I'm feeling particularly masochistic.
Anyone have other solutions?
Comment #27
lemuelsantos commentedSame thing... for me... Content Access NOT working at all:
Example:
I don't want Anonymous Users to access a specific content type... but no matter what I do on the "Access Control" page, they still seeing it...
The only is unchecking the "View Content" access on the permissions page... but then it affects everything globally not based on a content type only...
Comment #28
causalloop commentedlemudesign, have you tried other access control modules? I've tried just about all I can get my hands on and they all seem to have the same problem. The functionality appears to be there, but it just doesn't work. I feel like something is wonky with our installs. I'd be willing to bet that it would work fine on a fresh install of drupal...
Comment #29
causalloop commentedprogress. I got Node Privacy by Role to work. Possibly the same problem here. I realized I was installing the module in /var/www/modules instead of /var/www/sites/all/modules/ I had to do a re-build permissions after making changes to make it work, but now its working like a charm! (knock on wood...) Hope that helps.
Comment #30
salvis@causalloop: The 0/all/0/100 grant that you're showing has the correct explanation: All users may see all nodes.
This row should not be in the {node_access} table if any node access module is active, and usually it's removed by core, when you rebuild permissions. Have you tried that?
Comment #31
scrowther commentedI'm having the exact same problem, I cannot block anonymous from accessing particular nodes. I have spent so many hours trying not only Content Access, but also Node Access, Node Privacy by Role, and even Simple Access. I am starting to wish I had used Drupal 6 instead for this site. I'd appreciate any other suggestions, I've tried the suggestions from above (but I'm also not willing to mess with the db).
Comment #32
salvisIf you've tried rebuilding permissions and the 0/all/0/100 grant remains, then there are two possible scenarios:
1. You have no other node access module installed besides CA (i.e. no other module that defines hook_node_access_records(), or more specifically, no other module that defines a function composed of its module name followed by '_node_access_records'): it's a bug in CA, it writes that grant, probably by calling node_access_write_grants(). No contrib module should ever call node_access_write_grants(), see #237634: Rename node_access_write_grants() to _node_access_write_grants() and discourage its use.
2. You have other node access modules installed besides CA: any of them may be the culprit. Test each one separately (and rebuild permissions) to find out.
Comment #33
scrowther commentedThank you very much, this did the trick! On of the other modules caused the problem and rebuilding permissions worked.
Comment #34
dhalbert commented@scrowther: would you mind telling us which other module caused a problem, if you have narrowed it down?
Comment #35
gisleComment #36
gisle