I'm playing around with the ACL settings for administrator groups, and it seems kind of unfinished.

T.ex. we wanted someone to have access only to edit products, nothing else. But then we must remember to give access to image handling too (fine), but weirdly also categories, else they can't be selected any on the product... :)

And to be able to change own password, the user would need access to edit administrators. And when that access is given the user would be able to edit also others users accounts and passwords, including those with higher rights (e.g. full admins aka super admins).

Edit! Actually can a user with access to edit administrators also upgrade his own account to full access directly (changing user group). Ouch...
Tuesday, November 10 2015, 10:41 PM
Share this post:
Responses (3)
  • Accepted Answer

    Tuesday, November 10 2015, 10:52 PM - #Permalink
    Btw! Another thing is that the action buttons (edit, save) should be hidden if the user doesn't have rights to edit.
    The reply is currently minimized Show
  • Accepted Answer

    Monday, November 16 2015, 10:38 PM - #Permalink
    products, categories, buttons => It seems you're looking for a granular ACL. The current one is very simple, same as within OC.

    user => That must be definitely fixed.
    The reply is currently minimized Show
  • Accepted Answer

    Monday, November 16 2015, 10:54 PM - #Permalink
    Yeah, I'm looking for something better than OC for sure. ;) :)
    The reply is currently minimized Show
Your Reply