Login Keys Permissions Do Not Work Correctly.

alrnetwork

Verified User
Joined
Feb 12, 2021
Messages
164
Location
Europe UTC+2
Hi there,

I've been asked by a developer to provide them with login access to my control panel. I have the domain created as a "user" of the DirectAdmin interface, not a full Admin or Reseller. However, I'm having great difficulty managing their permissions.

Basically, unless I have "ALL_USER" in the "Allow" list, I will receive the following error:
Screenshot 2022-08-17 at 23.00.11.png

The thing is, if I allow "ALL_USER" then the rest of the options (such as disabling DNS access, Email access etc) are all visible.

I was working on the understanding that the login keys can be used to generate access to the panel without sharing your actual password and managing permissions, but it seems that either 99% of that functionality doesn't work, or that is not how it is intended.

I mean, they could literally use this to take over my own access by the looks of it.

Is this a bug or am I just doing something wrong?
 
Hello,

While all or some of the pages might become visible, in order to change anything they will need access to CMD_*. You might keep access to CMD_* disabled.
 
Right, so it isn't correct to think that by removing DNS access for example will also remove the icon from the panel. I would suggest that this is a feature improvement request.
 
While all or some of the pages might become visible, in order to change anything they will need access to CMD_*. You might keep access to CMD_* disabled.
I'm experiencing a different behaviour...
I created a key, allowed ALL_USER and denied anything relating to DB, both API and CMD... so i.e. I denied
CMD_API_DATABASES
CMD_API_DB_USER
CMD_API_DB_USER_PRIVS
CMD_DB
CMD_DB_ACCESS
CMD_DB_CREATE
CMD_DB_USER_CREATE
CMD_DB_USER_PRIVS
CMD_DB_VIEW

but it's ineffective... the user can use that keys to log-in, fully navigate in the menu, access all the db functions and do whatever he wants (change permissions, create a new db, create new users...)
Am I missing anything?
 
Never tried it by myself. You might open a ticket with DirectAdmin support and let them investigate the case.
 
Back
Top