[SOLVED] Why an Author can modify the uploaded file in the Production tab under Galleys?

Hi there,

Well i got this issue or problem , in where a submission that is already on the Production tab, the author can access this tab that is restringed by default and modify the galley content, this author do not hace access to this seccion, and much less permissions, except those assigned by the author profile, and verify the role and everything is in order, what it detects is that if the author is in the same network where OJS operates, he has access to the production tab and can modify the galley, but if you try to access it with the same credentials but using the data of your cell phone, it will give you denied access (this should happen in any network the author uses, block by profile type)

As you may notice this is a serious security problem because any author can modify the file of your shipment that is already in production, I have already reviewed the profiles and roles of users and everything is in order, the funny thing is that do not restrict access to the production tab to authors if they are connected from the same network in which the OJS system is operating.

I await your comments and possible causes as well as solutions to this.

Beforehand thank you very much

For the moment and due to this security breach, there is assignment of specific ports to access the production tab? this in order to be able at the moment to delimit the access, someone knows?

Hi @alienmau,

What version of OJS are you using?

Regards,
Alec Smecher
Public Knowledge Project Team

Hi, this is the actual version

Versión actual: 3.1.1.1 (julio 6, 2018 - 03:36 )

well, i think i found the problem, the autor privilege got activated the Editorial and production tab, i unchecked and all works correctly.

Hahaha problem solved, tnks any way

Hi @alienmau,

Just FYI, I did end up tweaking this behavior in the OJS 3.1.2 release:
https://github.com/pkp/pkp-lib/issues/4562

Regards,
Alec Smecher
Public Knowledge Project Team

1 Like