On the content type 'classroom' I'm using views_attach (http://drupal.org/project/views_attach) and nodereference_url (http://drupal.org/project/nodereference_url).

For permissions, I am using content_access (http://drupal.org/project/content_access) and acl (http://drupal.org/project/acl).

The content type 'students' has the nodereference field which is referenced to 'classroom'.

nodereference_url gives me the reference from url functionality allowing me to add a link to the page that I am referencing that allows me to create 'students' automatically referencing 'classroom'.

views_attach is also set up on 'classroom' to display a view of all nodes referencing it.

The content type 'classroom' has per content, per user access setup with Grant view access given to UserA.

I configured nodeaccess_nodereference on the 'students' nodereference field to Pass on view access.

As the super admin with permission to view everything the content and all fields are displayed. Without nodeaccess_nodereference configured I was unable to see any of the referenced 'student' fields. After using nodeaccess_nodereference to extend the permissions I am able to see the attached view but it is only displaying the title field.

Under permissions I have all fields set to view access by anonymous users.

CommentFileSizeAuthor
#4 Screen-shot-2011-08-01-at-3.50.13-PM.jpg65.41 KBd3str0y

Comments

d3str0y’s picture

By the way, this podcast from mustardseedmedia shows what my setup looks like (minus the permissions setup)

http://mustardseedmedia.com/podcast/episode37

danielb’s picture

Sorry I don't know those modules and I think therefore I also don't understand what the problem is. I'm not particularly interested in learning how 2 or 3 contrib modules work to find out what's going on, so unless you can point to something this module is doing incorrectly (in the code), I doubt anything will come of this.

danielb’s picture

A more likely solution would be for someone to write a module called "nodeaccess_nodereference_url" which duplicates the function from this module called nodeaccess_nodereference_node_access_records() as nodeaccess_nodereference_url_node_access_records() and changes it to work with nodereference_url fields?

d3str0y’s picture

StatusFileSize
new65.41 KB

I do not believe that nodereference_url has anything to do with this issue. nodereference_url only auto-populates a node reference field with a value from the URL making it easier to give someone a way to add nodes.

views_attach (http://drupal.org/project/views_attach) is the module that is creating the view that is not displaying all fields properly.

The view I've created with views_attach as per the module directions has an argument for the nodereference field in 'students', the default value of the argument in that view is set to "Node ID from URL". This way it displays all of the 'student' nodes referencing 'classroom'.

Without node reference node access enabled the user with grant view access cannot see the attached view (since each element in it's table is a node that doesn't have the user permission extended to it), when the module is enabled the view becomes visible but only displays the title field. See attached image for details. I've checked all the fields in permission and they are all enabled for view access by anonymous.

How can I check to see where the problem is occurring?

danielb’s picture

As a user who should get the permission through the reference, are you able to directly access the nodes listed in the view and see the field values output on the node page (assuming they are output there)?

Have you done any debugging on the views queries? Have you noticed any inconsistencies reported by the two Devel Node Access blocks?

d3str0y’s picture

Status: Active » Closed (fixed)

The problem was with Content Permissions (part of CCK in D6), I appreciate the support.

tosundar’s picture

I am having the same problem as you - and I am using views_attach as well. Can you describe the error you found with content permissions? May be I have a similar problem - though I looked carefully through the field permissions, and they are correct...

d3str0y’s picture

Hello tosundar,

Content permissions (part of CCK in D6) handles permissions differently than everything else under the permissions area. Usually if you apply a permissions to anonymous user it will grant access to every other type of role for that permissions. However, with content permissions you will need to check mark each role for each permissions.

Go to admin/user/permissions and you will see content permissions listed out under content_permissions as edit field_*/view field_*. Check each role you have that you would like to assign access to each permission individually.

Many people recommend http://drupal.org/project/field_permissions as a drop-in replacement for the Content Permissions module shipped with CCK so you may wish to check that out as well.

Hope that helps