Wrong permission checking for managing personal site pages
Description
causes
relates
Activity

Michael SaechangJune 12, 2012 at 10:26 AM
Thank you Pani for testing. Closing as 'Fixed'.

Pani GuiJune 10, 2012 at 11:49 PM
PASSED Manual Testing following the steps in the description.
Reproduced on:
Tomcat 7.0 + MySQL 5. 6.1.10 EE GA1.
User can create pages in his personal site even though he doesn't have Manage Pages permission with scope User Personal Site.
Fixed on:
Tomcat 7.0 + MySQL 5. Portal 6.1.x CE GIT ID: a8862abd594b2124c34fdc63d6e546202772941b.
Tomcat 7.0 + MySQL 5. Portal 6.1.x EE GIT ID: 708175f6569c96c0fc3915a4343f0182a63c1ac4.
Tomcat 7.0 + MySQL 5. Portal 6.2.x GIT ID: 65afa8dbb7d37f606e31f50ad6f85bc3882631ad.
User can't create pages in his personal site.

Michael SaechangJune 8, 2012 at 5:36 PM
Committed on:
Portal 6.1.x CE GIT ID: 8b42370f5da0d0fa7c27748217681d8837fef67a.
Portal 6.2.x GIT ID: 7bd273390bbd828fc90d7016a68e8c7cfeb95701.

Juan GonzalezMay 30, 2012 at 1:21 AM
Related issue:
Details
Assignee
Pani GuiPani Gui(Deactivated)Reporter
Sergio GonzalezSergio Gonzalez(Deactivated)Labels
Branch Version/s
6.1.xBackported to Branch
CommittedFix Priority
3Git Pull Request
Components
Affects versions
Priority
Medium
Details
Details
Assignee

Reporter

Labels
Branch Version/s
Backported to Branch
Fix Priority
Git Pull Request
Components
Affects versions
Priority
Zendesk Support
Linked Tickets
Zendesk Support
Linked Tickets
Zendesk Support

Steps to reproduce the issue:
1. Change the default permissions of the POWER USER role by removing the Manage Pages permission with scope User Personal Site (see attached screenshot)
2. Then, create a new user (he will automatically get the POWER USER role.
Then, the user can create pages in his personal site even though we removed the permission for doing it.