These forums have been archived and are now read-only.

The new forums are live and can be found at https://forums.eveonline.com/

Issues, Workarounds & Localization

 
  • Topic is locked indefinitely.
 

Roles of the "OTHER" kind

Author
Xander Hunt
#1 - 2012-05-21 15:51:30 UTC
So a corp mate brought to my attention a pretty damned severe security issue within the corp management that deals directly with roles.

My corp has many people using our POS, and each player (Not toon, but actual player) each is given their own division in a station, with one set aside for READ ONLY access to make copies of BPOs, and such.

However, its come to my attention that the "OTHER" role has a big hole that I don't understand. Maybe its intentional, but I can't fathom why.

Reading: http://wiki.eveonline.com/en/wiki/Roles_and_access_rights#Other

According to this, this means that if a toon is assigned a role for a particular division for OTHER, that toon will have access to any station division hangar that the corp has access to that isn't HQ or currently assigned to that toon, as well as access to the POS research stations, and such. So that means that if I give full access to the Div #3 (I call all divisions by numbers since we can only have 7 names across all corp hangars) with OTHER access, that means that EVERYONE IN THE CORP has access to Div #3 at ANY station the corp is renting from that ISN'T HQ or is assigned. Since the OTHER role has to be assigned to gain access to the research stations, my final question is WTF!?!?!

Seriously, if NO ONE at CCP is looking at this code and security model, let me officially request that either myself, or the community at large here, start work on some theoretical work that improves how this security system works. Personally, I'd gladly sign any NDA, AND give DNA (See what I did there?), given to me to get this security model working properly!!!
Xander Hunt
#2 - 2012-05-27 16:35:49 UTC
*bump*

No comment from anyone???