Page roles resetting. Is there any logging of page or module settings?

This is the place to report bugs and get support. When posting in this forum, please always provide as much detail as possible.

Please do not report problems with a custom build or custom code in this forum. If you are producing your own build from the source code and have problems or questions, ask in the developer forum, do not report it as a bug.

This is the place to report bugs and get support

When posting in this forum, please try to provide as many relevant details as possible. Particularly the following:

  • What operating system were you running when the bug appeared?
  • What database platform is your site using?
  • What version of mojoPortal are you running?
  • What version of .NET do you use?
  • What steps are necessary to reproduce the issue? Compare expected results vs actual results.
Please do not report problems with a custom build or custom code in this forum. If you are producing your own build from the source code and have problems or questions, ask in the developer forum.
This thread is closed to new posts. You must sign in to post in the forums.
5/22/2012 10:57:42 AM
Gravatar
Total Posts 19

Page roles resetting. Is there any logging of page or module settings?

Hi Joe,

This past week we had our security roles for 'View' changed on our home page without us knowing, which caused two of our sites to become unavailable.  We are suspecting someone is trying to hack our site, or perhaps it's just a user error, but we need to explore all possibilities.  Are you aware of any security issues or bugs that have been reported related to this issue?  We are running version 2.3.8.5 on both sites.  

Also, just wanted to make sure, does Mojo do any auditing on changes to settings?  It's really helpful to see version history on content changes, but it would also be useful to track on changes to page or module settings.  Especially in the case of multiple users who can edit the site and potentially shut things down through the page settings without any sort of tracking.

Thanks!

Sonny

5/23/2012 8:41:01 AM
Gravatar
Total Posts 18439

Re: Page roles resetting. Is there any logging of page or module settings?

Hi Sonny,

There was a bug (in version 2.3.8.1 I think) where when page permissions were saved it as not correctly updating the checkbox for all users in the UI. So the problem was if you didn't notice that All Users was unchecked and you saved the page settings again it would lose that setting.

That is my best guess of what happened, I don't think it was hacking or any kind of security bug. Sorry for the inconvenience.

We don't have any comprehensive audit trail for changes to settings. For the next release I will make it log it to the mojoPortal log as INFO when someone changes the view/edit roles of a page or module.

Best,

Joe

You must sign in to post in the forums. This thread is closed to new posts.