Post by scanreg » Wed Jun 26, 2013 2:24 am

i'd love a way to have a separate login directory for staff and admin

http://demo.opencart.com/admin-secret-location/
http://demo.opencart.com/staff/

it would be one more step to keep unwanteds out of the admin area

thanks

Active Member

Posts

Joined
Thu May 06, 2010 12:15 am

Post by butte » Wed Jun 26, 2013 2:49 am

Not new. Interpose directory passwording on the server, with its own user/pass, until the challenge is satisfied the admin log-in screen is not accessible. After that, OC itself takes care of admin levels by assigning "users" (admins) to "user groups" (admin groups). Many, probably most hosts' control panels provide for doing that without inserting .htaccess or other .ht* files manually for the purpose. Rename admin/ (ditto download/) and tell config.php files about that, flush vqmod cache if there is one, proceed. The two steps together prevent even getting to admin/ after possibly even guessing renamed/.

At this juncture there are quite a few even quite recent posts on just that.

Guru Member

Posts

Joined
Wed Mar 20, 2013 6:58 am

Post by scanreg » Wed Jun 26, 2013 10:28 pm

i actually don't want staff to know where the admin directory is at all

in fact, i wish there were a way to separate staff, admin, and a super admin location:

/staff/
/admin-secret-dir/
/superadmin-secret-dir/

Active Member

Posts

Joined
Thu May 06, 2010 12:15 am

Post by butte » Thu Jun 27, 2013 12:39 pm

When it's renamed they won't know where it is, without substantial computer savvy. At the log-in they won't know where it is. Once they log in, they'll see only what their preset permissions allow as users (admins) among user groups (admin levels).

Guru Member

Posts

Joined
Wed Mar 20, 2013 6:58 am

Post by straightlight » Sat Jun 29, 2013 11:47 pm

If you do not want staff to know where the admin directory is, the best solution I could provide would be by creating a ReWriteRule setting in your .htaccess so it would hide the original folder location on the URL.

Dedication and passion goes to those who are able to push and merge a project.

Regards,
Straightlight
Programmer / Opencart Tester


Legendary Member

Posts

Joined
Mon Nov 14, 2011 11:38 pm
Location - Canada, ON

Post by butte » Mon Jul 01, 2013 3:36 am

Perhaps most of us contemplating the problem, it would be a problem, of having a staff of "unwanteds" would not imagine changing or bothering to change the shopping cart in order to fix the problem. The admin permissions already provide the counterpart to having three or more differently notched car keys so as to keep valets out of glove boxes, trunks, etc.. If you have them tied to doing data entries, then you can set their admin permissions, but if they're "unwanteds" then you would actually be best off either letting them stuff raw product or other entries into a spreadsheet for the sake of export by your own hand into OC, or letting them go (poof). Any staff who would be bent upon mischief based upon directory names would find ways to do mischief based upon computers and files right in front of them.

Guru Member

Posts

Joined
Wed Mar 20, 2013 6:58 am
Who is online

Users browsing this forum: No registered users and 3 guests