Skip Navigation

[Resolved] Administrator only pages still viewable by guests

This support ticket is created 5 years, 12 months ago. There's a good chance that you are reading advice that it now obsolete.

This is the technical support forum for Toolset - a suite of plugins for developing WordPress sites without writing PHP.

Everyone can read this forum, but only Toolset clients can post in it. Toolset support works 6 days per week, 19 hours per day.

Sun Mon Tue Wed Thu Fri Sat
- 7:00 – 14:00 7:00 – 14:00 7:00 – 14:00 7:00 – 14:00 7:00 – 14:00 -
- 15:00 – 16:00 15:00 – 16:00 15:00 – 16:00 15:00 – 16:00 15:00 – 16:00 -

Supporter timezone: Europe/London (GMT+00:00)

This topic contains 26 replies, has 2 voices.

Last updated by Nigel 5 years, 5 months ago.

Assisted by: Nigel.

Author
Posts
#1157861

Yep, I found that ultimately the issue was with the selected '404' page, not so much with the default setting. Either applied directly to the user role, or 'globally' for all of those roles without access.

#1162790

Nigel
Supporter

Languages: English (English ) Spanish (Español )

Timezone: Europe/London (GMT+00:00)

Hi Mark

The Access developer proposed a fix, which is available as a patch until the next plugin update, as described here: https://toolset.com/errata/get-post-group-permissions-to-override-the-post-type-ones/

Can you try that patch to see if it fixes the problem?

#1166150

Hey Nigel,

Sorry for the delay. Applied the patch, and this appears to resolve this. So my understanding was the Post Type rules was overriding the Post Group?

This will be included in the next release so I am safe to upgrade at that point?

Cheers,
Mark

#1166256

Nigel
Supporter

Languages: English (English ) Spanish (Español )

Timezone: Europe/London (GMT+00:00)

Yes, that's right, and the next Access release will include the fix so you should be good to upgrade.

Just double-check when you upgrade that it still works.

#1202083

Hey Nigel,

Hope you are well sir.

Just a heads up -- doing maintenance on one of my main clients sites, and updated to the latest version of Access. Found that this version has a regression (sort of), in that it still seems to be affected by the same bug whereby any non-admin users can access 'admin only' items in a post group. It's as if the fix in the Helper.php file you linked was not rolled in. Any idea why? Is it safe to apply to Access 2.6.1?

Thanks,
Mark

#1202546

Nigel
Supporter

Languages: English (English ) Spanish (Español )

Timezone: Europe/London (GMT+00:00)

Hi Mark

I've asked the devs for clarification about this.

I'm not sure why they would have released an update that didn't include the fix, but it seems like that's what happened, so I've asked if they can confirm the same patch can be used.

I'll get back to you tomorrow.

#1202634

Thank you,
Mark

#1203493

Hey Nigel,

Any updates on this?

-Mark

#1203748

Nigel
Supporter

Languages: English (English ) Spanish (Español )

Timezone: Europe/London (GMT+00:00)

Sorry, yes, you can go ahead and apply the patch.

It didn't get included in this recent update because the update was unplanned and was pushed because of an issue that arose with the last Types update.

There should be a planned Access update—from the internal tickets and time that will be required for QA testing I expect that would likely be the week after next.

#1206703

Great, thanks Nigel. Applied the Access update and then applied the Helper.php on top. Seems fine thus far.

Cheers,
Mark

#1206853

Nigel
Supporter

Languages: English (English ) Spanish (Español )

Timezone: Europe/London (GMT+00:00)

OK, good, I'll mark this as fixed in next release again, so I'll know to remind you when the next release of Access is published.

#1260831

Nigel
Supporter

Languages: English (English ) Spanish (Español )

Timezone: Europe/London (GMT+00:00)

Hi Mark

I'm just doing some house-keeping and it seems I didn't update you to point out that Access 2.7 was released, which it has been, so you should be able to update without any issues, no need to re-apply the patch.