First...thx for a great tool. Far the best front end to rrdtool i've seen so far.
I'm running ver. 0.6.6 and like the new feature with user administration, but there are some "security" issues if u dont want users to see other users on the system or their graphs:
1) When u add a new graph, u have to go into user adm and under each user check DENY for this user. Would be nice to be able to choose a positiv list for each user.
2) If a user is Allowed to Keep Custom Graph Settings, he can see all other sections/users in the list even though he dont have access to it.
3) A user can always gain access to a graph by specifying the complete url with the appropiate id! (http://localhost/cacti/graph.php?graphid=XXX&rraid=all - replace XXX with an id of a graph)
/REM
User Administration "bugs"
Moderators: Developers, Moderators
Who is online
Users browsing this forum: No registered users and 1 guest