News:

RAID is not a replacement for a backup! Here's why.

Main Menu

Users with read permission able to delete folders

Started by Backdraft, August 17, 2019, 03:02:50 PM

Previous topic - Next topic

Backdraft

Hey,

Got a Buffalo LS441DF1 a few weeks ago and have been testing all the features. Today I discovered that I could delete folders and files over webaccess with a user account that only has read permissions for that specific folder. I set up this user account to be used on my phone so I don't accidentally delete anything off my NAS. I have backups on my NAS that I want to access on the go, but also make sure they are safe and that there isn't the slightest chance of being deleted by fumbling on the phone.

Later I discovered that if I change the folder attribute to "Read only" it would remove the ability to delete files, but it does it for all users. If I log in through webaccess with my admin account (which has read and write permissions) I can't delete files.

I'm now a bit perplexed as to what the user accounts and access restrictions should do.  They don't seem to do anything as far as read and write goes. Only the folder attribute,  Read / Read and Write seems to affect what I can do.




As3nd0r

Check you webaccess rights in folder setup, those are set up independently from the local rights unless you select "use inherited folder permissions". If you have set it to "allow groups and users" all users will have full access via webaccess unless folder is set to read only.

Aspirat primo Fortuna labori
Me duce tutus eris

Browser ID: smf (is_webkit)
Templates: 4: index (default), Display (default), GenericControls (default), GenericControls (default).
Sub templates: 6: init, html_above, body_above, main, body_below, html_below.
Language files: 5: index+Modifications.english (default), Post.english (default), Editor.english (default), Drafts.english (default), StopForumSpam.english (default).
Style sheets: 4: index.css, attachments.css, jquery.sceditor.css, responsive.css.
Hooks called: 135 (show)
Files included: 35 - 1354KB. (show)
Memory used: 1003KB.
Tokens: post-login.
Queries used: 16.

[Show Queries]