Uploaded image for project: 'Jahia Community'
  1. Jahia Community
  2. JAHIA-4111

ACL picker: please grey-out unavailable options - a read-only user can grant to himself or other some write or admin permissions without any warning or errors. nothing finally saved in DB

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Major
    • xCM 6.0
    • xCM 6.0
    • None
    • 24527

    Description

      There are no consistency checks in the new ACL picker. A read-only user on a content object can modify permissions in the UI.

      So for instance in the file manager, a john user with read-only permissions can modify ACL on a file or directory, save it (and it looks like being saved in the engines when toggling between tab). But when clising the file manager and reopening it, nothing was really save.

      Quite confusing.

      TestRail: Results

        Attachments

          Activity

            People

              tdraier_old Thomas Draier (Inactive)
              scroisier Stephane Croisier (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                TestRail: Runs

                  TestRail: Cases

                    Packages

                      Version Package
                      xCM 6.0