Login or Register

RSS IconRecent posts in this topic

avatar
SimonK on Jul 14. 2006. 6:00 pm
There appears to be a problem concerning rights. I created a client and two projects and granted the client rights to one project. When I log in as this client, his project is listed on the right. So far, so good. However, when I click this link and change the ID in the URL, whoops, there's project number 2. Hehe. I was only testing now and I'm pretty impressed, so I'm probably going to use this for my freelance jobs, though I don't think it's such a good idea when one client can view all other projects of other clients. ;)

I was actually surprised that this wasn't brought up yet, am I the only one playing with URL's all the time? :P It's probably something you overlooked. Other than this I think it's pretty stable, though I hope you're planning to make upgrading a bit easier. :) Great job, this tool wil make communicating a lot more easier.

Oh, by the way, the only thing your great app lacks is AJAX. It would make the use even easier than it already is, especially since I find my self clicking a lot of links (and thus refreshing quite often). But don't rush it, take your time to develop a good and stable app.
avatar
ashusta on Jul 14. 2006. 10:45 pm
Did you clear your cookie and reset your session or was it just a URL change that induced the behavior?
avatar
leeopold on Jul 15. 2006. 9:15 pm
I toyed with it and found the same issue. As a client, I changed the last part of the URL from

active_project=2
to
active_project=1

and had access to a project 1, where I was not a member. I could not download a PDF file or read messages from the link in the overview log, but I could view messages using the tab links.
avatar Staff
Ilija Studen on Jul 16. 2006. 3:53 pm
SimonK:
I was actually surprised that this wasn't brought up yet, am I the only one playing with URL's all the time? :P It's probably something you overlooked. Other than this I think it's pretty stable, though I hope you're planning to make upgrading a bit easier. :) Great job, this tool wil make communicating a lot more easier.

I overlooked it :( Permissions are really important in this kind of system so this will be fixed ASAP.

SimonK:
Oh, by the way, the only thing your great app lacks is AJAX. It would make the use even easier than it already is, especially since I find my self clicking a lot of links (and thus refreshing quite often). But don't rush it, take your time to develop a good and stable app.

XHR will use aC API to send async requests. So, API first, then AJAX.
activeCollab Team Member | Experiment: activeCollab on Twitter
avatar
SimonK on Jul 16. 2006. 8:41 pm
Nice, thanks. I wasn't able to test it with cookies/sessions cleared (see first reply) since my servers have been down since yesterday morning (yeah, the DreamHost fileserver thingie).

Quite funny by the way, I noticed my (test) client could not post new messages or anything: those links were hidden. So you did not overlook it completely... ;)
avatar Staff
Ilija Studen on Jul 16. 2006. 8:45 pm
Yes, aC have pretty strong permissions system but I missed to add checks on some pages. I think I'll create more flexible permissions system for 1.0, just to make a good foundation for future versions where will have extensible permissions for plugins and all the stuff we put in.
activeCollab Team Member | Experiment: activeCollab on Twitter
avatar Staff
Ilija Studen on Aug 20. 2006. 8:22 am
Fixed in SVN R32...
activeCollab Team Member | Experiment: activeCollab on Twitter
avatar
nolroos on Aug 28. 2006. 9:34 pm
Can this problem be solved with updating some files or do we have to wait until a next version? Thanks!
avatar Staff
Ilija Studen on Aug 29. 2006. 5:41 am
I'm afraid that things are a bit more complex than that - there are several changes in ProjectController plus some in other files and because this one was commited as part of a set of changes I can' isolate them.
activeCollab Team Member | Experiment: activeCollab on Twitter
avatar Staff
Ilija Studen on Jan 19. 2007. 1:43 pm
If you are wondering if this problem is fixed than just to point out: it has been fixed long time ago.
activeCollab Team Member | Experiment: activeCollab on Twitter
Topic is locked. If you have something important to say about issues discussed on this page please write at hi@a51dev.com.

RSS IconRecent posts in this topic