Skip to main content
Question

Role permissions for pages

  • July 3, 2019
  • 0 replies
  • 71 views

I've set up an app with a dashboard page that is open to EOTI. The purpose is for the public to see upcoming events, and register for them. It was all working great, until I realized that typing in ?a=showpage&pageid=X (where X= the page ID of the admin page) to the end of the URL allows them to access the dashboard page that was created for app administrators.

Since a hover on other parts of the app will show the basic schema of how to access the page, all it would take is replacing the pageID with the ID of the admin page for them to see the admin page.

Is there a way to restrict access to pages in the app for EOTI based on role or user settings? I'm worried that somebody could potentially view reports or records they shouldn't by modifying the URL in the address bar.
This topic has been closed for replies.

  • Quickbase Alumni
  • July 3, 2019
While it is true that they can go to those pages(I didn't know that until just now) they should not be able to see any data there. I tested this just now and I could go to the admin or any other page as the lowest role in my org but every page displayed nothing in the reports and some even said access denied.

If the report is displaying information to them then that is another issue. You should set the permissions for that EOTI role to be VERY restrictive in what tables and things they can see. If you have a table you do not want them to get info from make sure they are set to not be able to view, edit, or add to that table and if you want to go the extra mile you can make sure that is set at the field level as well. You can do that where some fields are allowed and some are not but safer way is to deny all. Only give them access to exactly the table they need and nothing else.