Opened 5 years ago

Closed 5 years ago

Last modified 5 years ago

#636 closed Bug (duplicate)

Concerns re: Anonymous access to SitesManager & Feedback

Reported by: acidie Owned by:
Priority: low Milestone: RobotRock
Component: Core Keywords:
Cc: Sensitive:


Ok, I posted this before, but vipsoft seems to think user access and anonymous access are the same thing and deleted it.

vipsoft> "Oops. Given ticket #554, we won't be blocking access to the site manager page."

They are not the same thing. but meh.

Anyway if you goto '/index.php?module=SitesManager&action=displayJavascriptCode&idsite=1' of any piwik install you will be granted access to that page without the need to log in.

Other pages are affected as well.

Personally if you restrict anonymous access to a site then ALL of that site should be blocked. Not a few pages or ones that count, but ALL of the site.

Feel free vipsof to delete this ticket, I can code so I will just fix the issue myself. But I thought I would be nice for your users (that can not code or dont have the time) to be able to trust 'NO ACCESS' truly means 'NO ACCESS'.

Change History (5)

comment:1 Changed 5 years ago by vipsoft (robocoder)

  • Priority changed from critical to low
  • Resolution set to duplicate
  • Status changed from new to closed
  • Summary changed from ANONYMOUS ACCESS TO ADMIN AREA to Concerns re: Anonymous access to SitesManager & Feedback

Dupes #635.

I apologize if my critique of your bug report hurt your feelings. (BTW Your ticket was only closed, not deleted.)

If I've misunderstood the scope and/or severity of the issues you raised, please feel free to elaborate and/or submit a patch.

comment:2 Changed 5 years ago by acidie

Personally I can't understand why you think anonymous users should be able to see any data when they are set to 'No Access'.

When I have security settings in software set to 'No Access' it should mean no access, at all.

But either way, I think it's an issue, but if you beg to differ, meh.

Apart from that, piwik is quite a nice program. I wish you the best of luck.

comment:3 Changed 5 years ago by matt (mattab)

(In [1039]) refs #636 for the sake of consistency, but this page does NOT show any data

comment:4 Changed 5 years ago by matt (mattab)

this page just takes the idsite and displays it, there is nothing confidential at all, especially as this page cannot be accessed via any link... for consistency I added the check though.

comment:5 Changed 5 years ago by matt (mattab)

  • Milestone set to RobotRock
Note: See TracTickets for help on using tickets.