Lock Out "Edit my Profile" Functionality

We have custom guest users that we need this functionality locked out completely and not obscurely. Of course we tried the suppression of the top bar already, but, its is still fairly possible for "creative" users to stumble upon the HTTP request parameter for it "in_hi_space=ProfileSettings", so we need these custom users to get locked out completely that even if they typed that request parameter in, they would be presented a login page or error since they do not have activity access to this piece of functionality. Problem is, by default, even these "custom" guest users are part of the "Everyone" group, and this group has this activity right by default. When we tried to remove it, we get the error in the page that states "...Group is locked, cannot apply any changes..." or something to that effect. Does anyone know some techniques in UI mod we can use to get around this problem with the "Everyone" activity rights modifications?
Ray Salgado, State of Maryland Project, 410.260.6083, [email protected]

Hi Ray,
Which version of the portal are you running? You should be able to remove the Edit Own Profile activity right from the Everyone group. If you are getting errors saying that it is locked, try going to the "Release Item Locks" utility and see if you can unlock the group from there. Then remove the activity right from the group.
Once you have that done, I would recommend creating a new group that is equivalent to the Everyone group, minus the custom guest user. Then re-add the activity right to this new group, so that everyone else can still edit their own profiles. What this will do is remove the Edit User Profile link from the My Account page for the custom guest user.
However, as you mentioned, a malicious user could figure out the URL and go to the editor directly. This is a bug and will be fixed in the next release. If you need to prevent users from such access to the editor, it will require you to customize the UserProfileEditorModel to check for the activity right when the editor first starts.
Another option is to remove Read rights for the custom guest user from each Property's ACL. The guest user will still be able to get to the editor, but because he doesn't have Read rights, he won't be able to edit anything. The only other thing is that he won't be able to View User Profile. But I'm guessing that since it's a guest user, there won't be much useful profile information anyways, right?
Let me know how these options work for you, and I can help you with whichever solution you choose.
Jennifer

Similar Messages

  • Contribute Locking out editable areas

    I am having a very strange problem that I am hoping someone
    can help me with. I have a site set up with a Dreamweaver template
    in which the main content area is an editable area. When I open the
    pages in Contribute it is still an editable area unless there is a
    bullet list, then it is still in a green editable area box, but
    gives me the "you can't edit this" mouse pointer and cannot be
    edited. If I got in and remove the <ul> ... </ul> from
    the html the area is editable again.
    Any help would be wonderful, I am going crazy here.

    OK, it has happened again, on a completely different site with a different user and (obviously) different template.  Here's the piece of the page which the CS5 Contribute "publisher" broke:
               <!-- InstanceEndEditable -->
          </div><img src="images/contentRight.jpg" width="53" height="734" alt="content right" style="float:left;" /></div>
        </div>
            <div class="clearfloat"></div>
            <p style="margin-top: 0; margin-bottom: 0;"> </p>
    <div id="footer">
                <p class="links"><a href="classinformation.htm">Class Info</a> |
                <a href="classes.html">Classes</a> |
                <a href="about.html">About Us</a> |
                <a href="register_choose.html">Register</a> |
                <a href="mailto:[email protected]">Contact Us</a> |
                <a href="reporting.html">Reporting Instructions</a> |
                <a href="index.html">Home</a></p>
                <p class="copyright">Site copyright &copy; 2011, Do It Right Protocol.</p>
                <p class="webguy" style="margin-bottom: 0;">Website hosted and maintained by <a href="http://www.maplegate-tech.com">Maplegate Technologies, LLC</a></p>
            </div>
        </div>
    </body>
    <!-- InstanceEnd --></html>
    I've bolded 3 items: the first is the template's end point for the editable region; the footer should not be editable.  The 2 changes show in the empty <p> above the footer div, and the addition of style attribute in the "webguy" paragraph.  Contribute should not have allowed those changes (I think they were made without the user even knowing about it).  The blank <p> tag broke the layout, forcing the graphics abart and adding a blank line.

  • Is it possible to lock out  the Key Board commands in Keynote?

    Is it possible to lock out your key board actions  in Keynote? This happened all of a sudden. My keyboard has no effect on my trying to change text colors or enter characters. By using the mouse to add text the text box appears but I cannot change the character color.I can change it with the mouse and the new color is displayed but when I type nothing appears as the default color is white and the background is white. I did a copy and paste from a previous slide and I can enter the line to start editing but nothing appears. Nor can I delete anything with the Key board. This is only happening in Keynote. If I use the Key Board to send an email everything works fine. Can type and use the delete button so it seems that the Key Board is fine with other Apps, this is just happening in Keynote. It seems like the Key Board actions are not taking place, it is as if the Key Board is locked out of the Keynote functions.
    Thanks in advance for any help
    Rodger

    Try resetting Keynote as follows:
    remove Keynote version 6.5, you must use an application removal tool for this procedure to work:    Appcleaner is free, I use Appzapper
    empty the trash
    Shut Down the Mac (Apple menu > Shut Down)
    wait 10 seconds, then press the power button
    Immediately after you hear the startup tone, hold down the Shift key, release the Shift key when you see the grey Apple screen
    start up will take a few minutes longer than usual as the Mac is performing a repair routine
    restart the Mac normally, (don’t hold down any keys during startup)
    install Keynote from the Mac App Store

  • Are parts of a pdf document in Adobe Acrobat Pro able to be secured so that once the recipient fills out a specific section, signs it, and submits it to the original sender, that information filled out is locked from editing for security purposes? If so,

    I have an application I'm submitting to our school website for potential students to fill out. There are sections for the student(s) to fill out as well as sections for staff to fill out. For the sake of security for the student filling out the form, I'd like to set it up so that once the student has filled out the proper sections and submits the information, any information filled out and signed by the student is locked from editing on my part. I only need to read what the student filled out and signed, then add my notes to Staff sections.  Is this possible? If so, how?  I need details!

    You can create a script that will lock the fields before signing. But when you edit the document after the student signs, the signature will no longer be valid and the document will show that it has been changed after signing. Adobe restricts the number of files you can collect information on with forms that can be saved and emailed. The restriction used to be 500 files unless you purchased the appropriate LiveCycle product to enable the pdf files for saving.
    Why in the world are you requiring potential students to sign forms. Many students will not know how to sign pdf files. Just have a button that will submit the information to a website for you to extract or to send you the information in an FDF file and import the information form. You can have a button that will lock the fields they fill out. This will ensure you do not have to worry about the 500 file limit.
    Understanding reader extensions licensing | Adobe LiveCycle Blog

  • Edit User profile Property - grayed out buttons

    I am trying to change the mapping for the Work email property in the User Profile but when I edit the property on the "Edit User Profile Property" page, the Property Mapping for Synchronization's "Remove" button is grayed out as well
    as Add New mappings "Add" button. I am logged on with the Farm account which has admin rights to  the UP.
    ITGirl

    Hi ,
    For the Add New Mapping's "Add" button grayed out, when I change to another/second "Synchronization Connection" from "Source Data Connection" dropdown, then "Add" button will be available.
    For the Property Mapping for Synchronization's "Remove" button grayed out,
    please make sure your Farm account or user account has the following permissions, then check results again.
    http://technet.microsoft.com/en-us/library/ee721049(v=office.15).aspx#MapUserProc
    The user account that performs this procedure is a farm administrator or an administrator of the User Profile service application.
    The user account that performs this procedure is a member of the Administrators group on the computer that is running SharePoint Server.
    Thanks
    Daniel Yang
    TechNet Community Support

  • Edit menu Copy function greyed out MSword 2011, v14.1.0 (after I updated to OS X 10.9.5; 4GB 1067 MHz, Processor 2.53 GHz, Intell Core i5)

    Edit menu Copy function greyed out MSword 2011, v14.1.0 (after I updated to OS X 10.9.5; 4GB 1067 MHz, Processor 2.53 GHz, Intell Core i5)
    The copy function under the edit menu is gone (greyed out) and the short-cut, "command + c" doesn't word. I can only copy by using the copy button on the formatting toolbar, which is slow & annoying. All after I ungraded to Maverick. I've tried several different solutions. Any suggestions? I've tried several solutions, but nothing has worked so far...

    Try posting in the Microsoft forum
    http://answers.microsoft.com/en-us/mac?auth=1

  • My printer crashed mid printing photo.  Printer works OK in other apps.  Now locked out in PhotoshopCC with error message: There was an error opening your printer. Printing functions will not be available until you have selected a printer and reopened any

    Ooops I put the lot in the strap line!
    My printer crashed mid printing photo.  Printer works OK in other apps.  Now locked out in PhotoshopCC with error message: There was an error opening your printer. Printing functions will not be available until you have selected a printer and reopened any documents.
    I would be grateful for help!!  Obviously...

    Probably best to ask in Photoshop General Discussion
    This forum is about the Cloud as a delivery process, not about using individual programs
    If you start at the Forums Index https://forums.adobe.com/welcome
    You will be able to select a forum for the specific Adobe product(s) you use
    Click the "down arrow" symbol on the right (where it says All communities) to open the drop down list and scroll

  • Transporting a business function: lock out users and suspend batch?

    Hi gurus,
    SAP advises in help.sap.com to lock out all users and suspend batch jobs before activating a business function in development.  I did that in development, activated the business function, and saved it to a transport.  Does the same recommendation to lock out users and suspend batch jobs hold true in the QA and Production systems when the transport is moved in? ... or is it ok to transport it during a time when there is user and batch activity going on?
    Warm Regards,
    CM

    You do have to lock out users and suspend batch, even using a transport.  There is a pdf called
    SAP Enhancement Packages Selecting and Activating Business Functions,  In it, it says to lock out users and stop batch activity in all systems,

  • Locked out of photoshop starter edition

    I have 500 pictures on my laptop under the expired photoshop starter edition.  I am locked out.  How do I move my pictures.

    Your pictures are just files in a folder somewhere on your harddrive. A simple search for a known file name in Windows Explorer will reveal their location.
    Mylenium

  • Corrupted/Locked out apple ID "An Unknown Error has occurred" logging into support?

    I was forced to use a different apple id to log into this support community because all attempts from different devices and browsers using another ID have ended up at the password prompt with "An unknown error has occurred" at the community login screen.  The ID can still be "manged" and appears to be able to make purchases from the iTunes Store over the internet.  A phone incident case number 388249960 was opened and I spent over an hour on the phone with this problem.  The ID in question was set up more than two years ago to help with my wife's iPad 1 which we paid 800 plus for,,, all the storage and bells and whistles.  Recently she started using the iTunes store to purchase and download television series and we got in trouble because her directories were filling the c:drive on a Vista Business computer she normally uses.  Before starting to deal with the problem of storage, I tried to make sure everything was up to date and downloaded/installed the latest iTunes 11.0,1,, to her machine.  I already had it on another machine running Windows 7 and two older Windows XP machines.    All of them were "tested" for home networking to our Apple TV so that I could go to the TV and find a computer which could be used as a source for streaming music, videos, etc., etc. all based on her ID.  As of this writing, I believe all of that functionality still exists, but, when I navigate to support and try to log in using her ID and password, I get re-prompted for the password and then "Locked Out" when "An Unknown Error Has Occurred" pops up above the login via the web site.
    I am writing this after much agony and travial via an obsolete instance of Windows Explorer running on Windows XP Home Premium on an old portable using a newly created Apple ID which does not appear to have the same problems logging into the support community.  Can anyone out there help me?
    I have gone to war with Comcast's "free" security enhancement software "Constant Guard" believing that it might be the source.  This machine had it installed at one time and has had it completely removed, but... it still experiences the error when my wife's ID is used.
    The issue may be related to the recently added requirement for secuity questions and recovery email addresses which I tried to address for her ID and inadvertently ran into conflict/problem with using certain other email addresses with her ID.  Perhaps something is corrupted in the database for her ID, or related to problems with support for esoteric things like Microsoft's .NET enhancements which I have long been using on my computers, or possibly Constant Guard "started" the problem because it was probably running when account security data was being updated via the Apple web site?  I tried to get information about what I thought was the "recovery email address" associated with her account and was told by Apple Web sites that it was "in use" as an apple ID and could not be used as her recovery address.  When I called trying to confirm that this ID was "mine" I was able to provide one of two security clearance pieces of data, but not enough information to get the support person to straighten things out for me. I ended up creating "yet another" ID just to get clear of the mess.
    I made a suggestion to one of the folks I spoke with that an improvement to the functionality of apple ID's would be to support "consolidation" of accounts so that if several different Apple devices had been registered with different ID's and they all belonged to the same user(s) that a "common ID" could be created.
    I'm reluctant to post apple ID's in a public support forum, and would prefer to deal with this by private email.  or phone.
    Message was edited by: [email protected]

    [email protected] wrote:
    I'm reluctant to post apple ID's in a public support forum, and would prefer to deal with this by private email.  or phone.
    Then contact Apple directly.
    This is a user to user technical support forum.  No one here has access to manage Apple ID's other than their own.
    There is no Apple presence here.

  • User settings reset and locked out of user folders ! How do I retreive?

    Hi everyone,
    I'm sure a number of people here on the forums have come across the problem with the blue tint that appears every now and then. It usually appears when connecting an external monitor after the you come back from the screen saver.
    Yesterday it happened for the first time without an external monitor connected. I have found a number of sites that have suggested using the command 'sudo chmod 664 *' within the Terminal. I have used it a couple of times to fix this problem but it did not work hence the reason it happened yesterday without a monitor connected. When I did use this command previously I first entered
    cd /library/colorsync/profiles/display
    When i did it for this occassion i forgot to enter the display folder first.
    After this I did a restart and all my user settings were reset and I was locked out of all my user folders. I lost all my desktop settings and everything was back to when I first started my computer.
    I did some hunting and found the command 'sudo chmod 777'. I tried this then did a reset and my desktop background returned and the folders were unlocked.
    What I want to know is if this is the correct command to bring everything back to normal?
    My user permissions in terminal are listed below
    Using the command sudo chmod 664 *
    drw-rw-r--+ 15 JoeBros staff 510 11 Jun 23:33 Desktop
    drw-rw-r--+ 19 JoeBros staff 646 22 May 20:44 Documents
    drw-rw-r--+ 46 JoeBros staff 1564 25 Jun 15:08 Downloads
    drw-rw-r--+ 45 JoeBros staff 1530 10 Jun 23:56 Library
    drw-rw-r--+ 4 JoeBros staff 136 1 Apr 19:19 Movies
    drw-rw-r--+ 38 JoeBros staff 1292 4 Apr 18:08 Music
    -rw-rw-r-- 1 JoeBros staff 92352512 29 May 18:20 Parallels-Desktop-5600-Mac-en.dmg
    drw-rw-r--+ 57 JoeBros staff 1938 25 Jun 16:02 Pictures
    drw-rw-r--+ 6 JoeBros staff 204 14 Jun 15:56 Public
    drw-rw-r--+ 5 JoeBros staff 170 26 Mar 00:59 Sites
    This is what is displayed after sudo chmod 777
    total 180376
    drwxrwxrwx+ 15 JoeBros staff 510 11 Jun 23:33 Desktop
    drwxrwxrwx+ 19 JoeBros staff 646 22 May 20:44 Documents
    drwxrwxrwx+ 46 JoeBros staff 1564 25 Jun 15:08 Downloads
    drwxrwxrwx+ 45 JoeBros staff 1530 10 Jun 23:56 Library
    drwxrwxrwx+ 4 JoeBros staff 136 1 Apr 19:19 Movies
    drwxrwxrwx+ 38 JoeBros staff 1292 4 Apr 18:08 Music
    -rwxrwxrwx 1 JoeBros staff 92352512 29 May 18:20 Parallels-Desktop-5600-Mac-en.dmg
    drwxrwxrwx+ 57 JoeBros staff 1938 25 Jun 16:02 Pictures
    drwxrwxrwx+ 6 JoeBros staff 204 14 Jun 15:56 Public
    drwxrwxrwx+ 5 JoeBros staff 170 26 Mar 00:59 Sites
    Does this look correct ??
    Any help would be great thanks

    I assume this access is open to everyone when I connecto any wireless network
    No necessarily, it depends whether you just changed your home folders and nothing else.
    But just your home folders present a problems as they should have extended attributes which are now removed. More on that later.
    Using one chmod to a directory affects all equally, though the files may have individually different permissions.
    I don't know how extensively you have altered the modes permissions, but from what you have shown in your first post your Home folders are incorrect.
    For your home folder, which is the default location when you start Terminal, and I dont think you have strayed from there, all the listings, except Parallels are folders, prefaced with the letter d. for folder.
    On my machine, for example, the pattern for the home folders all show
    drwx------@ 5 xxxxxx staff 170 25 Jun 06:07 Desktop
    normally that would be chmod 700 Desktop which will get you
    drwx------
    but note the @ which shows an extended attribute or ACL in Leopard.
    to write the ACL shown as @
    You will need to read
    man chmod about ACL MANIPULATION OPTIONS
    Personally, I think that playing around with chmod without a backup was not a good idea, and I wonder if your ambition has exceeded your knowledge. Sorry if that sounds tough, but a possible Archive and Install may be your safest path I think because what you have messed with was no small oops with a simple fix.
    You could just change those home folders to chmod 700 and see how it goes without the attribute, or bite the bullet and do an Archive and Install.
    I do not run parallels and so have no idea what is permissions should be.
    That Time capsule is starting to look pretty good now
    Message was edited by: roam2
    Message was edited by: roam2

  • Sleep grayed out in apple menu. MBPro stopped locking out.

    I have a MBPro we've been labbing with to utilize profile manager. After I transitioned some of the login screen preferences from workgroup manager to profile manager the client system/MBPro no longer will lock out when the lid is closed even though it's enabled under the security settings. The MBPro no longer has any profiles/mdm on it. I also noticed in the apple menu the sleep function/command is grayed out so you cannot select that option to make it go to sleep at all. Pre Mavericks I would assume one could dump the com.apple.systempreferences.plist, however it appears to not be so easy in mavericks. Any ideas for a quick fix on this? Thank you.

    Additional info. When pressing the power button to sleep the system this error comes up:
    4/14/14 10:45:15.950 AM loginwindow[83]: ERROR | SleepSystem | IOPMSleepSystem returned error: -536870174
    followed by this when selecting the sleep option. (the system does nothing when selecting sleep)
    4/14/14 10:45:13.556 AM com.apple.CrashReporter.ACRRDaemonPlugin[161]: Error saving state to file:///Users/xxxxxxxxx/Library/Application%20Support/CrashReporter/Intervals_5 2E8832E-75AF-5D0D-A0A1-6B5D79AA525E.plist
    4/14/14 10:45:15.950 AM loginwindow[83]: ERROR | SleepSystem | IOPMSleepSystem returned error: -536870174
    Still digging into it.

  • TS1702 iBooks will not update, now locked out of it. All books and PDF will be lost if uninstall. Ideas?

    iBooks will not update, now locked out. All books and PDF will be lost if uninstall. Ideas?

    Hi Email_user_02,
    Thanks for the post and welcome to the forum.  I am very sorry to hear you have been locked out of your email account.
    If I had to speculate as to what has happened I would think that when the home move order was placed your email address was not moved to your new account.  If your email is not linked to a broadband account or premium mail then the message you are receiving would be correct.  However its clear that this is our fault and I am really sorry about this. This is something that I can sort out.
    Can you please get your details off to me in an email?  Just click on my username, (SeanD) and you will find the 'Mods contact link' under the 'About me' section of my profile.  Once I have your details I will be able to confirm what has happened but more importantly I will ensure that nothing happens with this email address.
    Cheers
    Sean
    BTCare Community Manager
    If we have asked you to email us with your details, please make sure you are logged in to the forum, otherwise you will not be able to see our ‘Contact Us’ link within our profiles.
    We are sorry that we are unable to deal with service/account queries via the private message(PM) function so please don't PM your account info, we need to deal with this via our email account :-)

  • Admin lock out of guest loggin

    I am the admin and i have locked myself out of my guest profile. How do i reset the password to have access again. I tried by changing it in the admin profile and i had no luck. Help thanks

    Hi Ray,
    Which version of the portal are you running? You should be able to remove the Edit Own Profile activity right from the Everyone group. If you are getting errors saying that it is locked, try going to the "Release Item Locks" utility and see if you can unlock the group from there. Then remove the activity right from the group.
    Once you have that done, I would recommend creating a new group that is equivalent to the Everyone group, minus the custom guest user. Then re-add the activity right to this new group, so that everyone else can still edit their own profiles. What this will do is remove the Edit User Profile link from the My Account page for the custom guest user.
    However, as you mentioned, a malicious user could figure out the URL and go to the editor directly. This is a bug and will be fixed in the next release. If you need to prevent users from such access to the editor, it will require you to customize the UserProfileEditorModel to check for the activity right when the editor first starts.
    Another option is to remove Read rights for the custom guest user from each Property's ACL. The guest user will still be able to get to the editor, but because he doesn't have Read rights, he won't be able to edit anything. The only other thing is that he won't be able to View User Profile. But I'm guessing that since it's a guest user, there won't be much useful profile information anyways, right?
    Let me know how these options work for you, and I can help you with whichever solution you choose.
    Jennifer

  • Email account setup failed & now email account locked out

    I tried setting up my Blackberry Playbook (OS 2.0) with my work email account.  This failed for all three types of connections - Exchange, IMAP, and POP.
    Now an "external" server is trying to connect with that account at the place I work (University of Lethbridge) and still failing but causing account to be locked out.
    The IT department has traced the IP to 68.171.232.33.rdns.blackberry.net
    Evertime they "unlock" the account, it becomes locked again within seconds, because of requests from that IP to access my user account (which is also my email account credentials).
    I have tried shutting down the Playbook, but this does not help.
    I have wiped the Playbook and re-installed the operating system and upgraded to version 2.0 again, but again this has not helped.
    I have accessed my Blackberry account, but there is nothing to edit or change, regarding the email settings that I tried to use to connect to my email account at the U. of L.
    Any suggestions?
    Solved!
    Go to Solution.

    I had no problem setting uo a live.com account, but had issues with a POP 3 server, although I did'nt get "locked out". I found some advice in the official balckberry forums. Something to do with resetting the incoming port to 110. The second night i used the PB, I got it to operate correctly. Good luck, I am impressed with the functionality of the PB, but the POP 3 server was a little testy.

Maybe you are looking for

  • Error message when trying to use config editor

    I received the following error message when trying to deploy the changes to the device: CEDT0031: no command is available to download for the device X.X.X.X. REmove the device from the job and try again.

  • Error in 10.2.0.3

    Hi, A 30gb table with direct=y option in export 10.2.0.3 is getting failed with ora-01555 snapshot too old error. What is the best way to avoid the error? 1)Increase undo 2)Increase undo_retention 3)Use direct=n or anything else?

  • The "use a class customization to resolve this conflict" error

    Hello, I see most questions in this forum are unanswered, but here goes: I must be exceptionally thick, because in spite of finding several hits when searching for this issue, i still don't understand how to solve it: In the WSDL/schemas provided by

  • URL download at timer interval

    I want to capture the original JPG files posted by a webcam in the Arctic. This webcam places a new JPG image on the following URL each second. http://195.149.144.50/ImageHarvester/Images/icehotel_live.jpg I have created a simple Automater Workflow t

  • Graphs not appearing on my quality system

    Hi, On my R3 Quality system, we have developed an application using BSP for our MBO system,  which makes use of the Graphs. In the quality system we are able to see the graphs, in the quality system which in on HPUX 11.23 with Oracle 9i, it gives a m