Change WordPress user roles and capabilities Forums How to or FAQ User can access page even though they don't have the Selected User Roles

Viewing 4 posts - 1 through 4 (of 4 total)
  • Author
    Posts
  • #3898
    [email protected]
    Participant

    We have a page set up as follows:

    View Access: Allow View
    For Users: Selected User Roles
    bbp_keymaster (This is “Keymaster” role)
    Action: Show Access Error Message

    For some reason, we have a user that can still access this page, even though he does not have the bbp_keymaster role.

    We noticed that they can access the page when they have the “GA Site Administrator” role, which is a collection of many capabilities that seem distinct from the Keymaster roles as far as I can tell. When we remove the “GA Site Administrator” role, they get the access error message.

    Are there any capabilities that allow the user to access pages even though they do not have the role specified in the page setup? Seems like apparently there are, but I’m trying to figure out which ones, or why?

    Thanks.

    #3901
    [email protected]
    Participant

    I meant: “GA Site Administrator” role, which is a collection of many capabilities that seem distinct from the Keymaster capabilities as far as I can tell.

    Basically GA Site Administrator is unrelated to Keymaster, yet it gives users ability to see the page. This ability to see pages by those that are not in the specified group to view the page could be a security risk.

    #3905
    Vladimir
    Keymaster

    Hi,

    Can ‘GA Site Administrator’ role edit this page? URE does not apply content view restrictions to a page in case current user can edit this page. This is a default behavior.

    In case you need to change this, you can set a custom hook ‘ure_restrict_content_view_for_authors_and_editors‘.

    #3912
    [email protected]
    Participant

    That feature is fine, I just wanted to make sure I understand what was happening.

    Thanks.

Viewing 4 posts - 1 through 4 (of 4 total)
  • You must be logged in to reply to this topic.