• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • We are looking for U.S.-based freelancer or agency working with SEO or WordPress for a quick 30-min interviews to gather feedback on XOVI, a successful German SEO tool we’re looking to launch in the U.S.
    If you qualify and participate, you’ll receive a $30 Amazon gift card as a thank-you. Please apply here. Thanks for helping shape a better SEO product for agencies!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Issue User-Role Security issue in Obsidian?

g4marc

Basic Pleskian
Hi, we use Obsidian 18.0.24 on 5 physical Servers.
We hosted around 40 domains per server.
We set up another own server for one customer and migrated his web presence from one of the other servers.
Yesterday a customer logged in on the wrong server, on which his presence is not hosted.
He could log in with the user role "Domain Administrator" and see all Domains that are hosted on this server!
When searching for the problem, I found that all users from the other Server were migrated! But we migrated a SINGLE website only!
obviously this Users have access to the server, although the domains (subscriptions) are not stored there! They can see an administrate all hosted Domains,
even though they only have access to their own domain, which is not even hosted there!

It looks as if Obsidian grants access to all domains if a login via user roles exists (in my case "Domain-Administrator), but the assigned domain cannot be found on the Server.
How can that be?
 
Thank you for your report and detailed explanation of an issue. We are apologies for long silent. Actually an issue is under investigation now and we will reach you shortly with all the details.
 
Back
Top