Actions’button -> permission error

  • Posts: 58
  • Thank you received: 8
  • Hikashop Business
7 hours 11 minutes ago #371091

-- HikaShop version -- : 6.4.0
-- Joomla version -- : 5.4.4
-- PHP version -- : 8.3


Hi,

A customer with admin status (not Super Admin) can no longer perform any action in administrator/index.php?option=com_hikashop&ctrl=product. Although they can select a few products, click the ‘Actions’ button in the toolbar, enter the parameters in the popup, and click ‘Process,’ the following error message appears: 'Warning You don't have permission to access this. Please contact a website administrator if this is incorrect.'

With Super Admin rights, I can perform this function myself. In administrator/index.php?option=com_hikashop&ctrl=config#config_acl, the ‘Administrator’ group has all permissions for products and mass actions.

Is this a bug in the current version, or is there a setting that could prevent this action from occurring?

Regards
Stefan

Please Log in or Create an account to join the conversation.

  • Posts: 85360
  • Thank you received: 13949
  • MODERATOR
3 hours 24 minutes ago #371095

Hi,

It's both actually.
We did strengthen the default rules to be able to use actions. That's because with actions like MySQL and PHP a user with access to the backend could do virtually anything, including elevate his accesses.
So, the fact that your customer gets an error when trying to run an action is good. It means our security measure works.
However, combined with this we should also remove the actions button altogether so that users don't see something they can't use. We'll be fixing this.

Now, I did say "it's both", and that's because this error comes from the check of the Joomla ACLs on HikaShop. By default, only super administrators have access to custom fields, the HikaShop configuration, the edition of views and massactions.
If you wish to grant access to these to other groups, you want to check the ACL settings of HikaShop in the Joomla configuration page: administrator/index.php?option=com_config&view=component&component=com_hikashop
Then, if necessary, under the access level tab of the HikaShop configuration, you can fine tune access to the different parts of HikaShop in the backend.

Please Log in or Create an account to join the conversation.

Time to create page: 0.055 seconds
Powered by Kunena Forum