cestesud
Forum Replies Created
-
Hi Steve,
Yes, that’s exactly what I did – I added the user only to the subsite, NOT to the main site. But if that user logs into the subsite, they can then navigate to a page of the main site and they are able to see ALL pages of the main site, even though they are not in the user list at all for the main site, and even though the pages of the main site are blocked (using the Permissions plugin) for “Logged Out”, “Logged In”, “Everyone” and even for “Subscriber” (which is what this user is set up as within the departmental subsite).
Our main subsite uses the Permissions plugin to limit “Not Logged In”, “Everyone”, and “Subscribers” to only be able to view two specific pages that are set up there (a Login page and a “Not Authorized” page). This works correctly for all users who are listed in the Users list in the main subsite.
I created a second subsite for just one specific department of our staff. I also used the Permissions plugin within this subsite to limit “Not Logged In”, “Everyone”, and “Subscribers” to only be able to view two specific pages that are set up within that subsite (also a Login page and a “Not Authorized” page).
I want one user group (Student Employees) to only have access to the departmental subsite, not to the main subsite. I went to the second departmental subsite and added a user, set them as a subscriber and a Student Employee group type. Their permissions work fine within that departmental subsite to restrict access to certain pages in that subsite. But if that user goes to a page of the main subsite (which they haven’t been added to at all as a user), they can see all pages of that main subsite.
If I add that user to the main subsite user list as a Subscriber and add them to the Student Employee permissions group for that main subsite, then their permissions work correctly and restrict their access to pages of the main subsite. But if they are not added at all as a user in the main subsite, they see everything. I had thought in that case, they would be recognized when viewing a main subsite page as being in the “Everyone” group, or maybe the “Logged In” group and would not be able to see any pages. Instead it’s as if they are an administrator and can see all pages of the main subsite.