User control

Configure what frontend users can create or edit, how frontend uploads are handled, and how event registration and waiting-list promotion behave.

Version coverage: The main User Control options apply to JEM 5.0.1, JEM 5.0.2 Beta 1 and JEM 5.1.0 Beta 4. The resource-aware permissions described in the final section are specific to JEM 5.1.0 Beta 4.

Where to find these settings

  1. Log in to the Joomla administrator.
  2. Go to Components → JEM → Settings.
  3. Open the User Control tab.
  4. Review all four sections before saving the configuration.

Configuration at a glance

User Control

Configure frontend descriptions, image and attachment uploads, empty managed fields and IP storage.

AC - Events

Control who can create, automatically publish and edit events from the frontend.

Event Registration

Configure registration availability, invitations, comments and automatic waiting-list promotion.

AC - Venues

Control who can create, automatically publish and edit venues from the frontend.

User Control

OptionInitial valueDescription
Max. Length of Descriptions 1000 Defines the intended maximum length of event and venue descriptions submitted from the frontend. This compatibility option must not be treated as a security or database limit. Verify the behaviour of the frontend layout used by your site.
Image Uploads Optional Controls image uploads in frontend submission forms: Disabled, Optional or Required. Image format, size and resolution limits are configured in the Images settings.
Attachment Uploads Yes Enables or disables attachment uploads from frontend event and venue forms. File extensions and size restrictions are still applied by the attachment configuration and server limits.
Hide empty FE fields No Hides managed fields such as Type and Contacts from the frontend event form when no selectable records are available. Backend forms always display these fields.
IP storage mode Full IP address Selects whether a submitted IP address is stored as a full, anonymized or hashed value. This option is displayed only when Store IP is enabled in Settings → Basic Settings.
Privacy recommendation: Store IP addresses only when they are required for a defined operational or legal purpose. An anonymized or hashed value may still be personal data depending on how it is used.

AC - Events

These settings provide the traditional JEM frontend permission model. They do not grant access to the Joomla administrator.

OptionInitial valueDescription
Create Events Admins and JEM groups Determines who receives the frontend grant to submit new events. All Registered Users is a broad permission and should be used only when every logged-in account is trusted to submit events.
Autopublish Admins and JEM groups Determines who may publish a submitted event immediately. Otherwise, the event remains unpublished until it is reviewed and published by an authorised editor.
Edit ALL Events Admins and JEM groups Allows authorised frontend users to edit events created by other users. This is a powerful permission and should be restricted to trusted editors.
Edit Own Events No Allows a user to edit an event when the stored created_by value matches that user's Joomla account. It does not transfer ownership and does not grant permission to edit another user's event.
Understanding the two selector values
Admins and JEM groups
Does not grant the action to every registered user. The action may still be granted through Joomla permissions or membership of an appropriate JEM group.
All Registered Users
Provides the corresponding frontend grant to every authenticated user, subject to applicable content, category and resource checks.

Event Registration

OptionInitial valueDescription
Allow Event Registration Use Event Setting Choose whether registration is disabled globally, enabled globally, or controlled separately by each event.
Allow Invitation No Allows event creators to invite users and optionally restrict registration to invited users.
Allow Comments No Allows users to add an additional comment when registering for an event.
Automatic waiting-list promotion Yes Automatically moves eligible registrations from the waiting list when confirmed places become available. Select No when promotions must be performed manually by an event manager.
Automatic promotion strategy Strict queue order Selects how JEM processes the waiting list. This field is visible only when automatic promotion is enabled.

Strict queue order

Requests are processed in their original order. If the first request needs two places but only one is available, JEM waits until both places are available.

Recommended when fairness and queue order are the priority.

Fill available places

If the first request cannot be fulfilled, JEM may temporarily skip it and promote a later request that fits the available capacity.

Useful when maximising event occupancy is the priority.

AC - Venues

OptionInitial valueDescription
Create Venues Admins and JEM groups Determines who receives the frontend grant to submit new venues.
Autopublish Admins and JEM groups Determines who may publish a newly submitted venue immediately. Otherwise, the venue must be reviewed and published by an authorised editor.
Edit ALL Venues Admins and JEM groups Allows authorised frontend users to edit venues created by other users. Restrict this permission to trusted venue managers.
Edit Own Venues No Allows users to edit venues for which their account is stored as the creator.

Recommended configurations

Moderated community submissions
  • Create Events: All Registered Users
  • Autopublish: Admins and JEM groups
  • Edit ALL Events: Admins and JEM groups
  • Edit Own Events: Yes
  • Create Venues: Admins and JEM groups
Trusted editorial team
  • Create a dedicated JEM editor group.
  • Grant creation and editing through that group.
  • Enable autopublishing only when review is unnecessary.
  • Keep Edit ALL restricted to editors.
Closed event catalogue
  • Use Admins and JEM groups for every create/edit option.
  • Disable Edit Own for ordinary registered users.
  • Restrict frontend submission menu items.
  • Use Joomla ACL for administrator access.

What User Control does not configure

  • It does not grant access to the Joomla administrator. Backend access is controlled by Joomla ACL.
  • It does not configure event or venue deletion permissions.
  • It does not replace the Access Level assigned to an event, venue or category.
  • It does not configure category or event-type administration.
  • It does not override an explicit Joomla ACL denial.

JEM 5.1.0 Beta 4: resource-aware permissions

JEM 5.1.0 Beta 4 adds granular Joomla permissions for event categories and individual venues. The User Control values remain available as frontend compatibility fallbacks when the corresponding granular permission is not configured.

Permission precedence

Calculated permissionResult
Allowed The granular Joomla permission grants the action.
Denied The action is blocked. JEM does not bypass an explicit or inherited denial through User Control.
Not Set JEM may evaluate its traditional frontend grants, including User Control, Joomla component permissions, ownership and JEM groups.
Super User / core.admin The administrator override grants the action.
Category-aware event permissions

Event actions can be controlled for each JEM category, including creating, editing, editing own events, changing state and deleting.

An explicit denial in any assigned category blocks the action. When using granular category control, ensure every category assigned to a multi-category event resolves to Allowed.

Venue assignment permission

The Use Venue permission controls whether a user group may assign a particular venue to an event.

Frontend selectors show only eligible venues, and the submitted venue is checked again when the event is saved.

Example: category-specific event editor

  1. Create a Joomla user group named Community Editors.
  2. Open the required JEM category.
  3. Open its Permissions tab.
  4. Allow Create Events and Edit Own Events.
  5. Leave those actions Not Set or denied for categories the group must not manage.
  6. Log in with a real test user from that group.
  7. Verify both the visible category selector and a direct save attempt.

Troubleshooting

Check that the user is logged in, the submission menu item is accessible, Create Events is granted and at least one eligible published category is available.

Check Edit ALL Events, Joomla component permissions, category permissions and JEM group membership. Any of these may provide the edit grant.

Verify that Edit Own Events is enabled, the event's stored creator matches the current Joomla user and no applicable ACL permission is explicitly denied.

Check its publication state, Access Level and the current user's category or venue permissions. In JEM 5.1.0, also check the resource-specific Create Events or Use Venue permission.

Enable Store IP under Settings → Basic Settings. The storage-mode selector is hidden while IP storage is disabled.

Verification checklist

  • Test with a guest account.
  • Test with an ordinary Registered user.
  • Test with a user assigned to the intended JEM or Joomla group.
  • Test creating and editing both owned and non-owned records.
  • Verify unpublished submissions and autopublishing separately.
  • Verify category and venue selectors in frontend forms.
  • Test an unauthorised direct save, not only hidden buttons.
  • Test registration, cancellation and waiting-list promotion.