Loading...
 
Skip to main content

Category: User Administration (Registration, Login & Banning)

User Administration (Registration, Login & Banning)
Show subcategories objects

Name Type
Admin can't access when site_closed=y
When I set the site to closed in the general admin, I then can not login to open the site.
tracker item
Admin Cannot Validate New Users
I had tested this successfully in version 3.3, but now with the upgrade to version 4.0 it does not seem to work. Here are the steps to recreate the issue:

1. Set up a TikiWiki so that users need to be validated by an Admin prior to actually logging in.

2. Register as a new user and get the following message:

Your account request has been stored and will be activated by the admin as soon as possible.
You'll receive email notification once your account is activated.
Please do not attempt to login until you receive the email notification.

3. Log in as 'admin' and navigate to Users page of admin tools. Push the round green checkmark graphic which has a hover display that says "Validate user: junkman". It sends me to this URL:

http://www.mywebsite.info/tiki-login_validate.php?user=junkman&pass=n

On that page the site returns a simple dialog box that says "Invalid username or password". Who's username & password? The Admin's?

At this point it wants to redirect me to the home page and I cannot get these new users validated.
tracker item
Admin Log-in, when enabling/disabling "Use email as username" a conversion should be offered to manage previous user
At tiki-admin.php?page=login the admin can enable and disable "Use email as username" however there are side effects;

I have a working (upgraded) Tiki23 with plenty of registered users (username and email).
Now I want to change the log-in preference and to Use email as username.

At tiki-admin.php?page=login
Username
I enable "Use email as username”.

Technically, all seems to work;
I can login using the previous username and the email (good)
When registering a new user only the email field is displayed

But admin the users become harder.
At : /tiki-adminusers.php, the email column email doesn’t show up anymore, which make sense as now the user should show the email as username.
However for previous account that have a username and an email, the col user display their previous (existing) username.
And if I click on a user the first field is now “email” with the previous username value.

I have no way to find the email that are linked with users from the admin user.
Seems everywhere the field Email displays the previous username value (tiki-user_information.php, etc)
tracker item
Admin Log-in, When using "Use email as username" the username related settings shouldn't be applied
At tiki-admin.php?page=login , Username, when I enable "Use email as username" some username settings are now hidden (meaning not in use) but they are still applied.

Minimum length
Maximum length
(And may be "Force lowercase")

I created an instance to test and reproduce.
You need to "really" register a user, not using the admin user to create new users.

How to reproduce :
# Go to Admin, Control Panels and switch to "Advanced" (to see advanced preferences)
# Go to log-in : tiki-admin.php?page=login, Registration & Log in
# Enable : Users can register
# Disable : Validate new user registrations by email (we don't want to validate email)
# Go to : Username and set "Maximum length" to 6
# Apply (save)
# Use a different browser (check you are not logged), go to the Tiki and register a new user
# Try to input more than 6 characters for the username, you will see this error:
+ {img fileId="1689" thumb="box"}
# Go back to your previous browser (logged as admin), log-in : tiki-admin.php?page=login, Username
# Enable "Use email as username" option
+ The parameters Minimum length, Maximum length, (And may be "Force lowercase") will be hidden has not relevant anymore.
# Go back to your different browser (check you are not logged)
# Create a new user with an email for login (obviously longer than 6 characters).
+ You won't see an error on focus
# Submit your registration and you will see the error:
+ {img fileId="1690" thumb="box"}

The difference of treatment in the process make me think there is some wrong additional condition that should be cancelled if "Use email as username" is enable.
tracker item
Admin setting Log In, setting still apply on uncheck section
On the Admin section -> Log In -> Authentication method: Tiki

The setting Users can register is uncheck.
All the sub setting are hidden but some setting seams to still applied.

Example : If "Validate new user registrations by email" is checked the user will be forced to validate his email.
tracker item
Admin should be able to impose 2 factor authentication to users
{syntax type="tiki" editor="plain"}
On Tiki an admin can enable "Allow users to use 2FA" in the log-ion area /tiki-admin.php?page=login#Users Management

https://doc.tiki.org/Two-factor-authentication

But this step is not enough as __each user has to go individually__ to its user preferences (replace userId by an existing one) /tiki-user_preferences.php?userId=3#contentmytiki_user_preference-4 and enable it. So it is totally a user choice to use or not 2FA.

At /login or /tiki-login_scr.php?twoFactorForm if the user tries to login without a code pin he will simply login with his username and password.


We can consider very common for an admin to set __and impose 2FA__ for login into a site.
We should have an option to make it mandatory including links and/or email notification to allow users to set their Pin Code, etc.


In a previous version Tiki18 - 21 the feature was imposed to the users as when this feature was enabled, the user was forced to enter a code received by email. May be we could have both options as it was way much simpler and user friendly (easier).
tracker item
admin user + anonymous & registered groups NOT DELETABLE nor CHANGEABLE
After some bad experience (ours and from other users), Rick (Rick99) and I suggest:

^RFE should be that the following username should __not__ be changable or deletable:
* __admin__

And the following groupnames should __not__ be changable or deletable:
*__registered__
*__anonymous__

Additionally, there should be a usergroup __administrator__ that has ''all'' permissions. This would allow Tiki-admins to easily create new Admin logins, with their own usernames.
^

__added: ensure password reminder works out of the box__

A couple of usability issues could be fixed here.

a) remind/reset passwords is off by default - should be on?
b) no email is set on admin by the installer

this would prevent most newbie lost admin password issues i think. - mlpvolt


Last [http://tikiwiki.org/tiki-view_forum_thread.php?comments_parentId=24817&topics_threshold=0&topics_offset=0&topics_sort_mode=lastPost_desc&topics_find=&forumId=2|thread about it at tw.o here]


Related issue: http://dev.tikiwiki.org/tiki-view_tracker_item.php?trackerId=5&itemId=1074
tracker item
Admin user link from user registration validation page
I often want to edit users that request registration (such as add them to a group). It would be nice if the "user validated" page had a link to the page to edit that user's settings.
tracker item
Admin user: User (edit) link is not accessible when user tracker is used and has tabs
At tiki-adminusers.php (Admin users) there is a popover on the username that display the user information.
This popover should never overlap the username link.

While this work fine with the "usual" information it doesn't work when "user tracker" is used to store user informations (https://doc.tiki.org/User-Tracker) and have sections (tabs used).

{img fileId="1684" thumb="box"}
tracker item
Admin Users, RealName, composed realname order is not applied in admin interface (it is with the realname plugin)
On a Tiki23 I can use a user tracker to store information and in the admin => log-in control panel I can set the fields that should be used to display the user realname using "set user_trackersync_realname".

For exemple, in the user tracker I have
FieldId1 : user selector
FieldId2 : last name (Sfez)
FieldId3 : first name name (Bernard)

For "set user_trackersync_realname" I enter : 3+2
The realname should be "Bernard Sfez"

If I use the pluginrealname it will be displayed "Bernard Sfez". GOOD
However at the admin users list and some other places it will be displayed "Sfez Bernard". NOT GOOD

It used to work.

Instance couldn't be created...
tracker item
admin validation - new user account - can't login
new user can register but after admin validate his account user can't login because have no password in database

version: tikiwiki 1.9.9 - sirius
conf: allowRegister=y ; validateRegistration=y ; validateUsers=n
tracker item
Admin's "Switch to user" broken at tiki.org
At tiki.org, I wanted to switch to a particular user's account to check what his permissions were. I clicked "Switch to this user" in the Actions popup (over the wrench icon) and got an action confirmation dialog that I confirmed, and when the page refreshed, I was still logged in as admin, not the user. I didn't check yet at other sites to see if this problem is limited to tiki.org or general for branch 20.
---
Just noticed the same on another site and i think it's when there more users than -+user_selector_threshold+- so you get a search object selector. {sign user="jonnybradley" datetime="2020-02-25T10:22:10+00:00"}
tracker item
Admin>Groups>Groupname>Members Tab displays only 24 members (no mater how many more exist)
The group members tab is falsely capped, only displays 24 members, more exist in group when you check the admin>users screen.
tracker item
Admin>Login>User defaults or Admin>Groups: Ability to Subscribe new users to specific Tiki objects
{syntax type="tiki" editor="plain"}
It would be lovely to set some new user defaults at
* Admin (home) > Login > User defaults, and/or
* Admin > Groups > (Edit a single group)

The ability to Subscribe/watch/monitor new users in the site or to that specific group, to specific Tiki objects.

Which tiki objects?: I would say, in this order:
# specific forums
# specific blogs
# specific calendars
# specific newsletters (ML: we can already subscribe groups to newsletters)
# specific wiki pages
# specific structures
# specific trackers
# specific categories
# new articles

This is specially useful for new users of the site, where they don't know yet how to subscribe to specific areas, etc. Very needed for educational scenarios, but I can see many other places where new users are a bit lost for some time while they learn how to use the Tiki site.

Related:
*[wish988|Forum: Let forum admins/moderators add groups and/or users as watching the forum]
*[tiki-index.php?page=Business%20Plans|Let small business start ups access collaborative sharing where the document being shared is not visible by anyone else]


Anywhere there is a watch eye, it should be possible for an admin to have group members watch this category
tracker item
Adodb script errors on a new installation when working with groups
On a new installation of TikiWiki 1.9.4 (installed via Fantastico on a LAMP server), I get the following error:

Notice: Only variable references should be returned by reference in /home/hocho/public_html/wiki/tikiwiki/lib/adodb/adodb.inc.php on line 834

Warning: Cannot modify header information - headers already sent by (output started at /home/hocho/public_html/wiki/tikiwiki/lib/adodb/adodb.inc.php:834) in /home/hocho/public_html/wiki/tikiwiki/tiki-adminusers.php on line 414


All I did was create a new group and try to assign the group to a new user.
I also don't know why it is using ADOdb when I am using MySQL.

All other functionality of TikiWiki seems fine.
tracker item
afrog tino
This should be migrated to the community site, and handled with ((doc:Organic groups)) and ((doc:User Trackers))
tracker item
After upgrade 4.1->5.0 - Errors : 01 - Users maangement table :.tiki_trk_1 missing
Hello,

As I told about, after upgrading from 4.2 (I am testing from 4.3) many errors occurs. This theated in a glabal way in id4377.

After connecting as administrator if you submit "Users management" and try to modify a user preférences you will reach a

__fatal error__ :

Table "<your database>.tiki_trk_1" missing

You will find joined the htm saved from "page source code"


tracker item
After validation new users don't get redirected to their group home page
Have been trying to fix for several weeks, still can't manage it, but it's quite important i think (more or less has lost a Tiki client for me) {sign user="jonnybradley" datetime="2014-01-07T13:43:51+00:00"}
tracker item
Ajax
wiki
allow seing username in user tracker at registration time, step 2 (filling user tracker item)
I've set up a user tracker at registration time on tw.o, when TwCOmmunity group is chosen between the two listed right now at registration time.
http://tikiwiki.org/tiki-register.php

This tracker mainily requests selecting a checkbox to indicate that the user understands and will follow the rules and guidelines of TW Community, etc.

I've set up a user field at that tracker, so that we can see when each users decided to join TW Community by selecting that checkbox. And while the compulsory checkbox is not acting as compulsory (due to bug), which users did accept and which ones didn't accept.
http://tikiwiki.org/tracker8
tracker item
Allow to delete old non-valid registration requests + re-sending confirmation link to many users
{syntax type="tiki" editor="plain"}
Wishes:

# Option to allow deleting any user that was registered more than N days ago, and who still hasn’t passed the email validation step and/or the admin approval stage. Or through multiple selection of those users and click on "action on selected" delete. (ionce they are properly filterable). Wish from Alain.
+.
# Option to resend the confirmation email to the selected users
(in one server where we had intruders from time to time, and sys admins blocked php mailing for weeks, many users probably didn't get the validation email... And nowadays, I don't know how to split myself the requests by bots from the real users willing to join. I recently discovered (after upgrading to tiki 4.1 las week), that that site accumulated more than 100+ users like this...., among 500+ users in total. Wish from Xavi.
tracker item
Allow users to upload their profile photo avatar at registration time (through the user tracker)
Allow users to upload their profile photo avatar at registration time (through the user tracker)

The simplest approach, maybe, could be to allow the site admin to setup a tracker field of type "userPref" to handle the user avatar?

I know avatars are not user preferences (other things aren't but are treated as such for end users for the sake of usability simplicity, afaik)
See:
https://doc.tiki.org/User+Preference+Field
tracker item
Anonymous can read everything via search
When enabled feature_search it is possible for
Anonymous user to read protected pages via
special search request

Just try "a" or any other word that is in hidden
or protected area in search box - tiki-
searchresults.php give U text from hidden
pages

from tiki-searchresults.php



http://tikiwiki.org/tiki-view_forum_thread.php?
topics_offset=0&forumId=4&comments_parentI
d=16071
tracker item
Anti-spam measure - option to have automatic quarantine of forum posts that contain an external link
{syntax type="tiki" editor="plain"}
I think it would be good to have the option to have Automatic quarantine of forum posts that contain an external link. There would be an alert informing users that posts containing an external link will display after being approved by a moderator.

This would effectively end the kind of (likely AI or other automatic) spamming for link placement that we've seen in the tiki.org forums, I think.

This could be generalized to enable site admins to quarantine posts containing other content as well, such as hate speech. Maybe the admin preference would include a checkbox for "external link" and a text field for other content.

About the implementation, on the edit-forum page (such as tiki-admin_forums.php?forumId=14&cookietab=2#content_admin_forums1-2) there is an "Approval type" admin pref with options "All posted", "Queue anonymous posts", and "Queue all posts". To me the wording is a little unclear but maybe "Queue posts with external links" could be added here.

(I think "Require approval for" would be clearer than "Queue" in the wording of the options.)

It might also be good to extend this to also apply to comments, or to be ready to, if spam starts showing up there.
tracker item
every user has admin-permission
Any registed user can use "Switch User".

I think this is very important, because everybody is able to be admin. :-(

Or can i dit a Misconfiguration? I dont think so.

---

today i see, everybody IS admin! (but i don't assign admin-perms to these users)

---

I found the Problem:

if i have tiki_p_search-permission so i have all "tiki"-perms too :-(

- How can i configure a group (or all users / anonymous) that they can use "search" (most important function of a wiki, i think) whithout make them admin?
tracker item
Show PHP error messages