Results 1 to 5 of 5
  1. #1
    Join Date
    Feb 2007
    Posts
    37
    Plugin Contributions
    0

    Default Why have more than one admin user?

    Under Tools/Admin Settings is the capability to add more than one user who has admin access. Why is this feature built into Zen cart?

    I have just employed someone to help me pick and pack. If I process an order, changing the status from processing to Shipping, the username is not added to the screen showing that I did it. So there seems little point in setting up a new user for this employee.

    I know there is an add-on which can change the rights for each user, but I am curious to know what an out of the box Zen cart install offers for multi admin users?
    my greener home. Save money and save the environment.

  2. #2
    Join Date
    Sep 2003
    Location
    Ohio
    Posts
    69,402
    Plugin Contributions
    6

    Default Re: Why have more than one admin user?

    I own a nice online store ...

    I have 1 login for my admin ...

    I fire 3 disgruntled employees ...

    I forget to change my login information for a week ... :eeks:


    I have problems with my site ...

    I have 3 people working in the Admin but no one recalls doing anything to several products with problems ...

    Gosh ... if I just knew who was working on those problems ... maybe we could figure this out ...

    Oh lookie! There is an admin_activity_log ... and it shows who was working on the products in question and now we can work through what might have happened ...


    I like to use certain password patterns ...

    I fire 3 employees and remember to change my password ...

    Sneaky fellows figured out my new password based on old password patterns that they were aware of ...


    Multiple Admin logins are a good idea for a number of reasons ... security and tracing problems being the main issues ...

    Later, adding something like an Admin Manager also keeps people from being able to jump in where they shouldn't ...
    Linda McGrath
    If you have to think ... you haven't been zenned ...

    Did YOU buy the Zen Cart Team a cup of coffee and a donut today? Just click here to support the Zen Cart Team!!

    Are you using the latest? Perhaps you've a problem that's fixed in the latest version: [Upgrade today!]
    Officially PayPal-Certified! Just click here

    Try our Zen Cart Recommended Services - Hosting, Payment and more ...
    Signup for our Announcements Forums to stay up to date on important changes and updates!

  3. #3
    Join Date
    Jun 2007
    Posts
    89
    Plugin Contributions
    0

    Default Re: Why have more than one admin user?

    Leaving aside the naughty possibilities, it's also handy in case an admin forgets their password. If there is only one admin account, you're screwed (at least for a while).

  4. #4
    Join Date
    Feb 2007
    Posts
    37
    Plugin Contributions
    0

    Default Re: Why have more than one admin user?

    OK. That figures, and I thought that might be the reason.

    Then my question should be: where are these logs? I can find logs that have long lists of [GET] commands but I do not see a log that shows which admin user has accessed or changed things.

    Is there a configuration setting that determines if this is logged, and where?
    my greener home. Save money and save the environment.

  5. #5
    Join Date
    Jan 2004
    Posts
    66,444
    Plugin Contributions
    279

    Default Re: Why have more than one admin user?

    Admin Logging is *always* on.
    Another reason for having different admin users is for PCI compliance. All admin activity must be logged in order to know who has had access to what information and when.

    There's an Admin Activity Log Viewer addon available if you need to read who's done what.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

 

 

Similar Threads

  1. v154 Concurrent admin access / more than one simultaneous user
    By Haggis in forum Customization from the Admin
    Replies: 2
    Last Post: 1 May 2016, 09:38 PM
  2. How do i have more than 1 store on one website?
    By weblister in forum General Questions
    Replies: 3
    Last Post: 22 Nov 2011, 04:06 PM
  3. Can a product have more than one name?
    By labradors in forum Setting Up Categories, Products, Attributes
    Replies: 7
    Last Post: 5 Feb 2010, 12:09 AM
  4. Can I have more than one download folder
    By travel124 in forum General Questions
    Replies: 4
    Last Post: 11 Aug 2008, 05:22 AM
  5. Replies: 13
    Last Post: 28 Mar 2008, 11:30 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg