Skip to content

HTTPS clone URL

Subversion checkout URL

You can clone with HTTPS or Subversion.

Download ZIP

Loading…

Concerns re: Anonymous access to SitesManager & Feedback #636

Closed
anonymous-piwik-user opened this Issue · 4 comments

3 participants

@anonymous-piwik-user

Ok, I posted this before, but vipsoft seems to think user access and anonymous access are the same thing and deleted it.

vipsoft> “Oops. Given ticket #554, we won’t be blocking access to the site manager page.”

They are not the same thing. but meh.

Anyway if you goto ‘/index.php?module=SitesManager&action=displayJavascriptCode&idsite=1’ of any piwik install you will be granted access to that page without the need to log in.

Other pages are affected as well.

Personally if you restrict anonymous access to a site then ALL of that site should be blocked. Not a few pages or ones that count, but ALL of the site.

Feel free vipsof to delete this ticket, I can code so I will just fix the issue myself. But I thought I would be nice for your users (that can not code or dont have the time) to be able to trust ‘NO ACCESS’ truly means ‘NO ACCESS’.

@robocoder
Collaborator

Dupes #635.

I apologize if my critique of your bug report hurt your feelings. (BTW Your ticket was only closed, not deleted.)

If I’ve misunderstood the scope and/or severity of the issues you raised, please feel free to elaborate and/or submit a patch.

@anonymous-piwik-user

Personally I can’t understand why you think anonymous users should be able to see any data when they are set to ‘No Access’.

When I have security settings in software set to ‘No Access’ it should mean no access, at all.

But either way, I think it’s an issue, but if you beg to differ, meh.

Apart from that, piwik is quite a nice program. I wish you the best of luck.

@mattab
Owner

(In 1039) refs #636 for the sake of consistency, but this page does NOT show any data

@mattab
Owner

this page just takes the idsite and displays it, there is nothing confidential at all, especially as this page cannot be accessed via any link… for consistency I added the check though.

@anonymous-piwik-user anonymous-piwik-user added this to the RobotRock milestone
This issue was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Something went wrong with that request. Please try again.