ok I think i found it
the $user is not used anymore in the user_documents_permissions.class.php script
a new way is used to get the docgroup but the user is not used
if($_SESSION[’mgrDocgroups’]) {
$docgrp = implode(",",$_SESSION[’mgrDocgroups’]);
}
is the part where we get the docgroup(s) asignt to the current user
and in this part:
$tblsc = $dbase.".`".$table_prefix."site_content`";
$tbldg = $dbase.".`".$table_prefix."document_groups`";
$tbldgn = $dbase.".`".$table_prefix."documentgroup_names`";
$sql = "SELECT DISTINCT sc.id
FROM $tblsc sc
LEFT JOIN $tbldg dg on dg.document = sc.id
LEFT JOIN $tbldgn dgn ON dgn.id = dg.document_group
WHERE sc.id = $document
AND (1='' OR NOT(dgn.private_memgroup<=>1)".(!$docgrp ? "":" OR dg.document_group IN ($docgrp)").");";
// ^ MySQL 4.1 will not return the correct result if this statement is removed! ???
$rs = mysql_query($sql);
$limit = mysql_num_rows($rs);
if($limit==1) $permissionsok = true;
(I am not that good in reading mysql stuff) looks like it is searching if the current document is assignt to the docgroup of the current user (atleast that is what it should do)
so if there is one found then its ok to return true, somehow this query gives $limit = 1 even if the doc is not assigned to the current usergroup.