非管理员用户保存Magento配置时支付方法访问被拒问题排查
核心Mage_Paypal模块adminhtml.xml中的ACL权限错误分析
我最近在排查Magento后台权限问题时,发现核心Mage_Paypal模块的adminhtml.xml里存在一处ACL配置错误,导致paypal/general/merchant_country这个配置路径无法通过权限校验,直接触发"Access denied"异常。
问题出在app/core/Mage/Adminhtml/Model/Config/Data.php第170行的权限校验逻辑:
if (!Mage::getSingleton('admin/session')->isAllowed($configPath)) { Mage::throwException('Access denied.'); }
当系统校验paypal/general/merchant_country这个路径的权限时,因为adminhtml.xml里没有对应的ACL授权节点,所以会判定当前用户无权限,抛出访问拒绝的异常。
从你提供的adminhtml.xml片段来看,确实缺失了这个关键节点:
<acl> <resources> <admin> <children> <system> <children> <config> <children> <!-- 此处缺少paypal/general/merchant_country对应的ACL配置 -->
修复建议
- 首先找到Mage_Paypal模块的adminhtml.xml文件,路径一般是
app/code/core/Mage/Paypal/etc/adminhtml.xml - 在
<config>节点的<children>区域,补充对应的ACL配置:
<paypal translate="title" module="paypal"> <title>PayPal</title> <sort_order>300</sort_order> <children> <general translate="title"> <title>General Settings</title> <children> <merchant_country translate="title"> <title>Merchant Country</title> </merchant_country> </children> </general> </children> </paypal>
- 如果你的adminhtml.xml里已经有
<paypal>节点了,只需要在<general>的子节点中添加<merchant_country>这部分配置就行 - 特别提醒:按照Magento的开发规范,不要直接修改核心代码,建议通过自定义模块来重写或补充这个ACL配置,避免后续核心升级覆盖你的修改。
内容的提问来源于stack exchange,提问作者Marius Boia
相关产品推荐
相关产品推荐

