Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Groups
  • Search
  • Get Qt Extensions
  • Unsolved
Collapse
Brand Logo
  1. Home
  2. Behind the Scenes
  3. Qt.io webservices
  4. [solved][Groups] Security bug??? or not.
Forum Updated to NodeBB v4.3 + New Features

[solved][Groups] Security bug??? or not.

Scheduled Pinned Locked Moved Qt.io webservices
13 Posts 4 Posters 4.1k Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • V Offline
    V Offline
    vsorokin
    wrote on last edited by
    #1

    If I'm not right, delete this thread.
    I'm owner of Qt Linux group, I request new forum, but Admins connected "Desktop" forum with my group. And now, I move, edit, delete messages in "Desktop" forum. Is it normal? And yes I Dinosaur, and theoretical can moderate forum, but what will happen if I granted new owner for group who don't be Dino?

    Proof image.
    !http://habreffect.ru/files/023/3544b3edb/securitybug.png(Security bug)!

    --
    Vasiliy

    1 Reply Last reply
    0
    • G Offline
      G Offline
      giesbert
      wrote on last edited by
      #2

      Hi Vass, You are owner of Linux Group, I am owner of Window sgroup, so I think we are admins of "our" Forum, which is defacto the "QtDevelopement\Desktop". I see the same.

      Nokia Certified Qt Specialist.
      Programming Is Like Sex: One mistake and you have to support it for the rest of your life. (Michael Sinz)

      1 Reply Last reply
      0
      • V Offline
        V Offline
        vsorokin
        wrote on last edited by
        #3

        Yes, I thought as much. Well, Hello fellow moderator ;)

        --
        Vasiliy

        1 Reply Last reply
        0
        • S Offline
          S Offline
          stukdev
          wrote on last edited by
          #4

          This is strange, if i normal user create new forum and connect to desktop, he can edit delete or anythink he want on the desktop.
          Is this correct?

          1 Reply Last reply
          0
          • V Offline
            V Offline
            vsorokin
            wrote on last edited by
            #5

            stuk Not quite, forums connect through request to admins. If admins decide connect existing forum to your group, then yes.

            --
            Vasiliy

            1 Reply Last reply
            0
            • S Offline
              S Offline
              stukdev
              wrote on last edited by
              #6

              Ok, but this sound like 'a workaround to moderate a section of forum without have the necessary level'.

              [quote author="Vass" date="1292531788"]stuk Not quite, forums connect through request to admins. If admins decide connect existing forum to your group, then yes.[/quote]

              1 Reply Last reply
              0
              • G Offline
                G Offline
                giesbert
                wrote on last edited by
                #7

                But as you are the owner of the group, you are admin of the group. So it makes sense that you are also admin of the groups forum. Up to this it nmakes sense, like in german group, Volker is damin as he created the group.
                But in our case, we were connected to an existing forum group, so there we are now also admins.

                Nokia Certified Qt Specialist.
                Programming Is Like Sex: One mistake and you have to support it for the rest of your life. (Michael Sinz)

                1 Reply Last reply
                0
                • S Offline
                  S Offline
                  stukdev
                  wrote on last edited by
                  #8

                  Ok that owner has the power to control all the you want, this is correct!
                  I only said that for me is strange this 'workaround' because why a group want a forum when at the end the group use the desktop forum? Use the normal desktop forum and don't create a group forum no?

                  [quote author="Gerolf Reinwardt" date="1292532391"]But as you are the owner of the group, you are admin of the group. So it makes sense that you are also admin of the groups forum. Up to this it nmakes sense, like in german group, Volker is damin as he created the group.
                  But in our case, we were connected to an existing forum group, so there we are now also admins.[/quote]

                  1 Reply Last reply
                  0
                  • G Offline
                    G Offline
                    giesbert
                    wrote on last edited by
                    #9

                    I think, that is the idea of the Trolls. If you have a group that would fit to a sub forum, conect it to that. If not, create a new forum (like for languages).

                    Nokia Certified Qt Specialist.
                    Programming Is Like Sex: One mistake and you have to support it for the rest of your life. (Michael Sinz)

                    1 Reply Last reply
                    0
                    • M Offline
                      M Offline
                      mgran
                      wrote on last edited by
                      #10

                      As has been stated here earlier, to connect a forum to a group requires admin action. And as the owner of the group we also trust you with moderating the forum connected to it.

                      To get help with moderation you can join the Site Moderator group, or hang with us on the IRC channel. If you feel it was a bit too much responsibility you can let us know, I'm sure we can figure something out.

                      It's based on trust, and if you love Qt - what can possibly go wrong? :)

                      Project Manager - Qt Development Frameworks

                      1 Reply Last reply
                      0
                      • G Offline
                        G Offline
                        giesbert
                        wrote on last edited by
                        #11

                        We were just a bit suprised :-)

                        Nokia Certified Qt Specialist.
                        Programming Is Like Sex: One mistake and you have to support it for the rest of your life. (Michael Sinz)

                        1 Reply Last reply
                        0
                        • S Offline
                          S Offline
                          stukdev
                          wrote on last edited by
                          #12

                          @mariusg: Ok, if is your choice i accept this.

                          1 Reply Last reply
                          0
                          • V Offline
                            V Offline
                            vsorokin
                            wrote on last edited by
                            #13

                            mariusg Thanks you for trust for us. I am flattered.

                            --
                            Vasiliy

                            1 Reply Last reply
                            0

                            • Login

                            • Login or register to search.
                            • First post
                              Last post
                            0
                            • Categories
                            • Recent
                            • Tags
                            • Popular
                            • Users
                            • Groups
                            • Search
                            • Get Qt Extensions
                            • Unsolved