The website is working OK and I now want to give Steve permission to proofread and edit some of the pages, So I set steve up as a back end user, create a user group for Proofreaders and enter steve as a member of that group. I then create a document group (Text only) for pages which only have text and include document 68 in it. Then I link the Proofreaders user group to the Text only documents group. When steve logs in he can see document 68 but when he clicks to edit it he is told that he does not have enough privileges. Is there some other setting which I should have made?
Laurie Fox
Go Security --> Roles, click your manager user and give him permissions!
That had been done already. Some of the funny results I was getting seem to have been due to running steve’s access on one tab on Firefox and my admin access on another tab. I have now changed to tests by "steve" being made on a different computer in the network. Steve can now edit pages in the Text only document group but I find that he can also edit pages which are in the site admin document group and not in the text only group. There is no link between the site admin document group and any user group. Why should this be?
Laurie Fox
Quote from: laurie at Mar 08, 2009, 03:54 PM
Steve can now edit pages in the Text only document group but I find that he can also edit pages which are in the site admin document group and not in the text only group. There is no link between the site admin document group and any user group. Why should this be?
See if this helps:
http://bobsguides.com/permissions.html
Bob
Thanks for quick reply. I am afraid that the suggested guide does not help in this case. I looked at the somewhat similar document in the Wiki a day or so ago and my setup is exactly as recommended there. The problem is that manager users can see and make changes on documents outside their allocated permissions. I agree with your point about using a separate browser for a manager user and for admin when testing.
However I suspect that others do not have this problem so it is likely that there is something wrong with my set up and I am trying to find out what it is. The tests I am making are on a copy of the existing website and I can always make another copy and start again. Maybe the database I am currently working on has got corrupted by the recent tests using two different tabs in Firefox. I certainly got to the stage then when one of the displays said that it was steve who had logged on (upper right) but the "info" tab said it was me (admin). That caused me to go to separate computers for the trials.
Laurie Fox
That is an odd one. The only thing I can think of to suggest (before trashing the site) is to create a new user with the same rights and see if it still happens. Be sure to clear the site cache and cookies before testing your changes.
Also, since you made a copy of the site, double check manager/includes/config.inc.php on both sites to make sure they are connected to separate databases. You might also check .htaccess to make sure the rewrite rules aren’t sending users on one site to the other site (where the permissions would be different).
Bob
I have tried with a fresh user (alfred) but still get the same results. So I will start again and make another copy of the original with a fresh database. I have several databases available so I won’t need to scrap the apparently corrupted one at this stage as I might want to look at it again later to see what happend. The config.inc.php’s are OK. I will keep you posted.
Regards
Laurie Fox
Bob
Things are all right now. Some of the pages were still public so I created a "non public" document group and put them in that. The database now works as it should and when steve logs in as manager he only sees the pages for which he has permission. This has been done by using different browsers on a single computer, and, of course, making sure to refresh. The previous difficulties were with using separate tabs on the same browser.
Laurie Fox
I’m glad you got it worked out.

Thanks for reporting back so others can learn from your experiences.
Bob