?
avatar PhilETaylor
PhilETaylor
24 Apr 2017

Steps to reproduce the issue

Install Joomla 3.7.0
Create a custom field of type media with full defaults
Login to the front end as an Author, ready to submit your new content...

Expected result

That a front end "Author" (A User with "Author group membership") should be able to select some media in the custom field

By default, the ACL for "Edit Custom Field Value" is inherited, which is denied.

Actual result

When submitting content on the frontend, an Author can only see the default value (or nothing) and cannot click the missing select button to launch a modal to select some media.

One would assume that an Author should be able to select something for this field?

screen shot 2017-04-24 at 21 16 48

avatar PhilETaylor PhilETaylor - open - 24 Apr 2017
avatar joomla-cms-bot joomla-cms-bot - change - 24 Apr 2017
Labels Added: ?
avatar joomla-cms-bot joomla-cms-bot - labeled - 24 Apr 2017
avatar PhilETaylor PhilETaylor - edited - 24 Apr 2017
avatar PhilETaylor PhilETaylor - change - 24 Apr 2017
The description was changed
avatar PhilETaylor PhilETaylor - edited - 24 Apr 2017
avatar joomla-cms-bot joomla-cms-bot - change - 24 Apr 2017
Title
[com_fields] A frontend Author has no ACL to set new media in com_fields
A frontend Author has no ACL to set new media in com_fields
avatar joomla-cms-bot joomla-cms-bot - edited - 24 Apr 2017
avatar PhilETaylor
PhilETaylor - comment - 24 Apr 2017

Yes I know you could mess with the ACL to achieve this, but we should be providing sound defaults for the shipped default usergroups for each type of field in com_fields

avatar franz-wohlkoenig franz-wohlkoenig - change - 25 Apr 2017
Title
A frontend Author has no ACL to set new media in com_fields
[com_fields] A frontend Author has no ACL to set new media in com_fields
avatar joomla-cms-bot joomla-cms-bot - change - 25 Apr 2017
The description was changed
avatar joomla-cms-bot joomla-cms-bot - edited - 25 Apr 2017
avatar joomla-cms-bot joomla-cms-bot - change - 25 Apr 2017
The description was changed
avatar joomla-cms-bot joomla-cms-bot - edited - 25 Apr 2017
avatar joomla-cms-bot joomla-cms-bot - change - 25 Apr 2017
Title
A frontend Author has no ACL to set new media in com_fields
[com_fields] A frontend Author has no ACL to set new media in com_fields
avatar franz-wohlkoenig franz-wohlkoenig - change - 25 Apr 2017
Category ACL com_fields
avatar franz-wohlkoenig franz-wohlkoenig - change - 25 Apr 2017
Title
A frontend Author has no ACL to set new media in com_fields
[com_fields] A frontend Author has no ACL to set new media in com_fields
avatar franz-wohlkoenig
franz-wohlkoenig - comment - 9 Jun 2017

@laoneo any Thoughts on this Issue?

avatar franz-wohlkoenig franz-wohlkoenig - change - 9 Jun 2017
Status New Information Required
avatar joomla-cms-bot joomla-cms-bot - edited - 9 Jun 2017
avatar laoneo
laoneo - comment - 10 Jun 2017

From a security point of view, I would go the way that an admin needs to actively activate the right permissions for non super admins. So I would leave it as it is. But I'm just a developer and not a security expert.

avatar Bakual
Bakual - comment - 10 Jun 2017

You could set the global ACL settings for this action in the database. We can adjust that for new installations. But we can't do it for upgraded sites.

avatar franz-wohlkoenig franz-wohlkoenig - change - 19 Aug 2017
Status Information Required Closed
Closed_Date 0000-00-00 00:00:00 2017-08-19 12:17:26
Closed_By franz-wohlkoenig
avatar joomla-cms-bot joomla-cms-bot - close - 19 Aug 2017
avatar franz-wohlkoenig
franz-wohlkoenig - comment - 19 Aug 2017

closed as stated above.


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/15518.

avatar joomla-cms-bot
joomla-cms-bot - comment - 19 Aug 2017

Add a Comment

Login with GitHub to post a comment