Home

drupal.ls.net

Navigation

  • About
  • Blogs
  • Contact
  • Forums
  • Image galleries
  • Log in
  • Feed aggregator
Home Blogs faustus's blog
    • Drupal
    • LSNet

Core security advisories

  • SA-CORE-2010-002 - Drupal core - Multiple vulnerabilities
more

Contrib security advisories

  • SA-CONTRIB-2010-089 - Simplenews Content Selection - Cross Site Scripting
  • SA-CONTRIB-2010-088 - Content Construction Kit (CCK) - Access Bypass
  • SA-CONTRIB-2010-087 - GovDelivery - Cross site scripting
  • SA-CONTRIB-2010-086 - Prepopulate - Access Bypass
  • SA-CONTRIB-2010-085 - Pathauto - Cross Site Scripting
more

Drupal security announcements

  • PSA-2010-002 - Views - Administer views permission
  • PSA-2010-001: Policy on release versions and permissions
more

Drupal.org jobs feed

  • Marketing Website Developer | Western Governors University
  • Coder | Fidoli Bilişim Teknolojileri
  • Drupal developer | ubergig
  • Javascript developer | ubergig
  • Web Developer | MIT
more

Visit our client's websites

  • http://bridle-creek.com
  • http://demo.mydllurth.com
  • http://downtowngalax.com
  • http://drupal.ls.net
  • http://crossleft.org/
  • http://cuttingedgelaw.com/
  • http://new-river.dixongarner.com/
  • http://import.mydllurth.com
  • http://lyceum.mydllurth.com
  • http://mtvaleumc.org
  • http://news.mydllurth.com
  • http://oldcranks.com
  • http://psychguides.com
  • http://starbuck.net
  • http://stewartfurniture.com
  • http://tarvid.org
  • http://ubercart.ls.net
  • http://wolfeservices.net

Events

« September 2010
SunMonTueWedThuFriSat
1234
567891011
12131415161718
19202122232425
2627282930

Anonymous, authenticated, trusted

Submitted by faustus on Sat, 01/09/2010 - 14:58
  • Anonymous users should have read privileges only.
    • admin/user/permissions - remove privileges except possibly:
      • access news
      • access announcements
      • access printer-friendly version
      • access comments
      • access site-wide contact form
      • access content
      • access notify
      • access print
      • access send to friend
      • access quotes
      • access service links
  • Authenticated users should be moderated.
    • admin/content/types/ - edit every content type workflow settings to "In moderation queue" including but not limited to:
      • announcements
      • blog
      • book
      • event
      • forum
      • image
      • page
      • petition
      • poll
      • quotes
      • story
      • tellafriend
      • webform
  • Trusted users can bypass moderation.
    • install modr8
    • install modr8_bypass
    • admin/user/roles - create a role e.g. "trusted user"
    • admin/user/permissions/ - necessarily a judgement call, add posting permissions for those entries you do not want to moderate for trusted users
    • admin/content/node/overview - review posts to identify users you want to "trust"
    • open the candidate account in a new tab or window
    • choose "edit"
    • add the role "trusted user"
  • Moderated users can become "trusted", "blocked" or "deleted"
    • If a moderated post has merit, edit the poster's account and add the role "trusted user"
    • if the post lacks merit, either delete the post and or edit the users account and change active to blocked
    • I am looking for workable criteria to delete accounts. Inactivity seems to be the safest route at the moment, after all, the purpose in having members is to add their content when appropriate

 

  • faustus's blog
  • Login or register to post comments
  • Printer-friendly version
  • Send to friend
  • PDF version
  • Delicious
  • Digg
  • StumbleUpon
  • Facebook
  • Google
  • Technorati

User login

What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Powered by Drupal, an open source content management system
RoopleTheme