Support Forum

Changed permission ranking on PM plugin?

23 Answers

New Answer

DH Dietmar Herian
Dietmar Herian
Member

Mr Papa said
whoa… just reread your first post… and think we all might have overlooked something…

you said you gave them guest permission…  guests by definition are not allowed to send private messages – how could they?  they dont have an account/inbox/etc…  and if you look at the permissions panel, there is an icon next to the pm permission that says the permission is ignored for guests…

They are getting this because of the default user group mapping

but being in the guests usergroup and being identified as a guest can be two different things… 

do you have this guests usergroup mapped to the default guests group?

Yes, it is mapped to default.

do you get the same result if you try a similar dual membership but not have one of them linked to the default guests usergroup? (ie copy the guests usergroup to another usergroup and assign that new usergroup as the default usergroup for guests)… I will try to run similar testing…

I am afraid, I did not quite get you! How can I copy a user group? Do you mean ‘move users to a new user group’?

If I did that, they are moved to the new user group and I would get the same but only different names.

If I remove the guests user group from their membership, they have instantly access. the same is true for any other combination of two user groups where one of them has no access to pm

YS Yellow Swordfish
Yellow Swordfish
Member

If I remove the guests user group from their membership, they have instantly access. the same is true for any other combination of two user groups where one of them has no access to pm

Well this actually answers the question Steve asked I believe. So can you confirm that you have actually tried this dual membership neither of which is the ‘Guest’ group and only one of the groups having PM permission?

If so then we can investigate the Guest user group more closely to see what factor is at play here.

DH Dietmar Herian
Dietmar Herian
Member

Yellow Swordfish said

If I remove the guests user group from their membership, they have instantly access. the same is true for any other combination of two user groups where one of them has no access to pm

Well this actually answers the question Steve asked I believe. So can you confirm that you have actually tried this dual membership neither of which is the ‘Guest’ group and only one of the groups having PM permission?

If so then we can investigate the Guest user group more closely to see what factor is at play here.

Yes, it can be confirmed!

As soon as I add a second user group with no pm permission, access is disabled.

As soon as I remove the second group, access is enabled for this user.

YS Yellow Swordfish
Yellow Swordfish
Member

I am sorry but these two statements

…they have instantly access. The same is true for any other combination of two user groups where one of them has no access to pm.

and

As soon as I add a second user group with no pm permission, access is disabled.

contradict each other. Which is the right one please. We need to be sure what exact situation is when it comes to attempting to replicate it.

DH Dietmar Herian
Dietmar Herian
Member

Yellow Swordfish said
I am sorry but these two statements

…they have instantly access. The same is true for any other combination of two user groups where one of them has no access to pm.

and

As soon as I add a second user group with no pm permission, access is disabled.

contradict each other. Which is the right one please. We need to be sure what exact situation is when it comes to attempting to replicate it.

Not sure what you mean!

I wrote ‘is disabled’ trying to express that users do no longer have access to pm. In my eyes, this is exactly the same like statement 1:  ‘has no access to pm’.

As I always said: the lower permission is overriding the higher one! Or out of two contradicting permissions, the lower one wins!

 

MP Mr Papa
Mr Papa
Member

But you are missing the point of the question. The guests usergroup is a unique, distance usergroup and not like other user groups.

Andy’s question was do you get the same behavior if you do it with two normal user groups, ie ones not mapped to the default usergroup.

In testing last night on multiple sites, could not duplicate your issue – the best permission always wins out, not the worst. And no one else has reported similar problem either. But my testing did not use the default guest usergroup and it’s non standard to actually put members into this usergroup, so ight be related to this hence the questions.

DH Dietmar Herian
Dietmar Herian
Member

Mr Papa said
But you are missing the point of the question. The guests usergroup is a unique, distance usergroup and not like other user groups.

Andy’s question was do you get the same behavior if you do it with two normal user groups, ie ones not mapped to the default usergroup.

Yes, I did. I created a normal user group for testing purposes, combined it with the members ug and result was no access to pm. I removed the test user group and result is having access to pm

In testing last night on multiple sites, could not duplicate your issue – the best permission always wins out, not the worst. And no one else has reported similar problem either. But my testing did not use the default guest usergroup and it’s non standard to actually put members into this usergroup, so ight be related to this hence the questions.

Not to be misunderstood: I did not put them into the guests user group, they are automatically in the guest user group because of the default mapping. Initially I thought once a user registers thus acquiring membership to the members user group, the guest user group is deleted because no longer needed. As this was not the case , I left it as it was. So far, there was no probllem with this. Only recently, by some action however, this principle stopped working. We were asking ourselves what has been done in this time frame, but nobody could remember that any action has been taken on the forum.

If the right way is to delete them from the guests user group, I’ll do that. I do not need dual group memberships.

But anyhow, you have access to the admin area. It can easily be seen in live action there.

You are referring to a ‘standard’. Is there a description available how to set up this standard? I never found one and obviously, our understanding of user groups is different from yours.

 

DH Dietmar Herian
Dietmar Herian
Member

While writing my last reply, I had another thought.

Definition, who has access to pm is done in the permission sets, users are assigned in user groups. They come together when you set up a forum or forum group – there you map permission sets to user groups.

From what forum or forum group is the pm permission derived if there are several different ones and no global permission set defined?

Should there be a global permission set over all forums? Currently, there is none!

MP Mr Papa
Mr Papa
Member

global permission?  think you misunderstand that…  that will just apply a given usergroup and permission set to all forums in the groups…  but you wont see it as global, it just gets added at each forum…

guests are visitors to your site who do not have an account and are not logged in… they do not have a user id…  so when guests visit, they have to be given some sort of permissions/access on your forum…  so they get the permissions as defined on the default guests usergroup…  there was never any intention for actual users to be part of the guests usergroup…

that said, there should not be an issue if you do assign users to the guests usergroup… but since we cannot replicate your issue, trying to narrow it down and gather more data…  if you had the same problem with two non guests usergroups, then it would give us something to go on…  I plan to try this test myself – though not sure I will get to it tonight…

Also, can you try this with another permission?  may be for the same two usergroups, give one permission to upload an avatar and one that cannot…  see if you can upload an avatar…  again, just more data for us…

our permission system check know nothing about the actual permission… so if for some reason it was selecting the lesser of the two permissions, it would do this for all permissions – not just pm, because its an API and doesnt even know what permission its checking…