Home

drupal.ls.net

Navigation

  • About
  • Blogs
  • Contact
  • Forums
  • Image galleries
  • Log in
  • Feed aggregator
Home Blogs faustus's blog
    • Drupal
    • LSNet

Core security advisories

  • SA-CORE-2010-001 - Drupal core - Multiple vulnerabilities
  • SA-CORE-2009-009 - Drupal Core - Cross site scripting
more

Contrib security advisories

  • SA-CONTRIB-2010-029: Keys - Cross-site Request Forgery
  • SA-CONTRIB-2010-028 - Tag Order - Cross Site Scripting
  • SA-CONTRIB-2010-027: Email Input Filter - Arbitrary code execution
  • SA-CONTRIB-2010-026 - Monthly Archive by Node Type - Access Bypass
  • SA-CONTRIB-2010-025 - TinyMCE - Cross Site Scripting (XSS)
more

Drupal.org jobs feed

  • Drupal web programmer & user interface integrator | National Renewable Energy Laboratory (contract)
  • Drupal, PHP, MySQL, AJAX developer | Brillient Corporation
  • Principal Engineer | REI Systems
  • Webbdesigner | NodeOne
  • Webbutvecklare | NodeOne
more

Visit our client's websites

  • http://bridle-creek.com
  • http://demo.mydllurth.com
  • http://downtowngalax.com
  • http://drupal.ls.net
  • http://crossleft.org/
  • http://cuttingedgelaw.com/
  • http://new-river.dixongarner.com/
  • http://import.mydllurth.com
  • http://lyceum.mydllurth.com
  • http://mtvaleumc.org
  • http://news.mydllurth.com
  • http://oldcranks.com
  • http://psychguides.com
  • http://starbuck.net
  • http://stewartfurniture.com
  • http://tarvid.org
  • http://ubercart.ls.net
  • http://wolfeservices.net

Events

« March 2010 »
SunMonTueWedThuFriSat
123456
78910111213
14151617181920
21222324252627
28293031

Anonymous, authenticated, trusted

Submitted by faustus on Sat, 01/09/2010 - 14:58
  • Anonymous users should have read privileges only.
    • admin/user/permissions - remove privileges except possibly:
      • access news
      • access announcements
      • access printer-friendly version
      • access comments
      • access site-wide contact form
      • access content
      • access notify
      • access print
      • access send to friend
      • access quotes
      • access service links
  • Authenticated users should be moderated.
    • admin/content/types/ - edit every content type workflow settings to "In moderation queue" including but not limited to:
      • announcements
      • blog
      • book
      • event
      • forum
      • image
      • page
      • petition
      • poll
      • quotes
      • story
      • tellafriend
      • webform
  • Trusted users can bypass moderation.
    • install modr8
    • install modr8_bypass
    • admin/user/roles - create a role e.g. "trusted user"
    • admin/user/permissions/ - necessarily a judgement call, add posting permissions for those entries you do not want to moderate for trusted users
    • admin/content/node/overview - review posts to identify users you want to "trust"
    • open the candidate account in a new tab or window
    • choose "edit"
    • add the role "trusted user"
  • Moderated users can become "trusted", "blocked" or "deleted"
    • If a moderated post has merit, edit the poster's account and add the role "trusted user"
    • if the post lacks merit, either delete the post and or edit the users account and change active to blocked
    • I am looking for workable criteria to delete accounts. Inactivity seems to be the safest route at the moment, after all, the purpose in having members is to add their content when appropriate

 

  • faustus's blog
  • Login or register to post comments
  • Printer-friendly version
  • Send to friend
  • PDF version
  • Delicious
  • Digg
  • StumbleUpon
  • Facebook
  • Google
  • Technorati

User login

What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Powered by Drupal, an open source content management system
RoopleTheme