Commit 95281234 authored by Chris Graham's avatar Chris Graham
Browse files

Fixed MANTIS-4041 (Document that permission to add/edit catalogues is high risk)

parent d29976ff
Loading
Loading
Loading
Loading
+2 −0
Original line number Diff line number Diff line
@@ -230,6 +230,8 @@ Like other Composr content types, catalogues support access permissions. However

If you manually alter the templates so that upload/picture fields display the raw URL, rather than going through Composr's downloader script, then you will need to delete the [tt]uploads/catalogues/.htaccess[/tt] file. By default permissions are denied to directly access these URLs, to prevent users without catalogue access from accessing individual files.

Note that assigning permissions to add/edit whole catalogues comes with a high risk -- as permission to post any Comcode/HTML effectively comes with permission to add the catalogue.

[title="2"]Customising the look & feel of catalogues (advanced)[/title]

If you have multiple catalogues on your website and you wish for them to have customised appearances, this is possible for advanced users via one of two ways: