Details
-
Improvement
-
Resolution: Fixed
-
Neutral
-
None
-
None
-
None
-
None
Description
Restricting user accounts on public instances
Ref - http://forum.magnolia-cms.com/forum/thread.html?threadId=bd703c72-4bf1-441c-8690-372661961b5a
Two docu updates required.
In admin/security add:
Workflow solution:
Reduce number of accounts needed on public using workflow for activation. Superuser account is the only one needed (plus the users you want to grant direct access to).
IP based solution
Allow access to /.magnolia* URI only from the IP that belongs to author instance (and possibly from extra few IP addresses from which you want to be able to login to AdminCentral).
In http://documentation.magnolia-cms.com/workflow.html
Link to security page and mention that for the public instance superuser account is the only one needed (in addition to users with direct access rights).