close ad
 
Important WebAssist Announcement
open ad
View Menu

Technical Support Forums

Free, outstanding support from WebAssist and your colleagues

security questions

Thread began 12/01/2009 9:25 am by office377308 | Last modified 1/08/2010 12:58 pm by office377308 | 2082 views | 7 replies

troyd

I've got something strange here that I am not figuring out. I installed an instance of HTMLEditor with Advanced File Management. But it is confused about my Security Assist rules selected in the Global settings interface.

Here's the details. The is an insert page within a CMS created a long time ago using DA and SA. It's been secured using an Admin login rule and the page itself will deny access if you are not logged in. However, if I am logged in and try to upload a file using HTMLEditor and the fckeditor "Upload File" tab, it denies me and a error drops down saying that it is disabled in the config.php.

If I have it set to "Everyone" it works. And if I have it set to my "Administrator" rule it fails. But here's the weird part. If I have it set to "Administrator" only, but then I log out, and then click upload, it works. I did this by opening a new window and then logging out and then returning to the instance of the tabbed "Browse Server" window that was still open).

The HTMLEditor folder is in my root directory. In my case (/public_html/HTMLEditor/) and my insert page is in (/public_html/CMS/admin/insert.php)

The upload knows where the correct path is. So I am assuming it is something I am overlooking with my SA rules. Keep in mind, the rule I am using is the exact same rule that denies access to the page the editor is on, if not logged in.

By the way, this rule is a session that checks the global.php page where the admin username and password is located. So the HTMLEditor code might not know where to compare the username and password. Is that a possibility? Should I add the

php:
<?php require_once( "../Globals/globals.php" ); ?>

to some page within the HTMLEditor folder?

I noticed that within the tables created by HTMLEditor, there is a parameters table with username "" and password "". Should I edit this?

Any thought?

Thanks,
TroyD

Build websites with a little help from your friends

Your friends over here at WebAssist! These Dreamweaver extensions will assist you in building unlimited, custom websites.

Build websites from already-built web applications

These out-of-the-box solutions provide you proven, tested applications that can be up and running now.  Build a store, a gallery, or a web-based email solution.

Want your website pre-built and hosted?

Close Windowclose

Rate your experience or provide feedback on this page

Account or customer service questions?
Please user our contact form.

Need technical support?
Please visit support to ask a question

Content

rating

Layout

rating

Ease of use

rating

security code refresh image

We do not respond to comments submitted from this page directly, but we do read and analyze any feedback and will use it to help make your experience better in the future.

Close Windowclose

We were unable to retrieve the attached file

Close Windowclose

Attach and remove files

add attachmentAdd attachment
Close Windowclose

Enter the URL you would like to link to in your post

Close Windowclose

This is how you use right click RTF editing

Enable right click RTF editing option allows you to add html markup into your tutorial such as images, bulleted lists, files and more...

-- click to close --

Uploading file...