Closed (fixed)
Project:
Web File Manager
Version:
6.x-2.9-alpha2
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
8 Jan 2009 at 14:34 UTC
Updated:
18 Jul 2010 at 19:15 UTC
It appears to me that the Web File Manager settings page, i.e., http://xxx.org/admin/settings/webfm, is available to users with permission to "access administration pages," without regard to their "administer webfm" permissions setting.
I would think these settings are part of the administration of webfm. In any event, I believe there should be a setting to remove permission to view or change settings on this page.
I have users who I would like to authorize to perform some admin tasks, e.g., changing user settings such as blocked and active, but who I do not want to play with OS level settings like web settings.
Comments
Comment #1
nhck commentedThanks for reporting this, imho this has been fixed?