Wrong permission checking for managing personal site pages

Description

Steps to reproduce the issue:

1. Change the default permissions of the POWER USER role by removing the Manage Pages permission with scope User Personal Site (see attached screenshot)
2. Then, create a new user (he will automatically get the POWER USER role.

Then, the user can create pages in his personal site even though we removed the permission for doing it.

Activity

Show:

Michael SaechangJune 12, 2012 at 10:26 AM

Thank you Pani for testing. Closing as 'Fixed'.

Pani GuiJune 10, 2012 at 11:49 PM

PASSED Manual Testing following the steps in the description.

Reproduced on:
Tomcat 7.0 + MySQL 5. 6.1.10 EE GA1.

User can create pages in his personal site even though he doesn't have Manage Pages permission with scope User Personal Site.

Fixed on:
Tomcat 7.0 + MySQL 5. Portal 6.1.x CE GIT ID: a8862abd594b2124c34fdc63d6e546202772941b.
Tomcat 7.0 + MySQL 5. Portal 6.1.x EE GIT ID: 708175f6569c96c0fc3915a4343f0182a63c1ac4.
Tomcat 7.0 + MySQL 5. Portal 6.2.x GIT ID: 65afa8dbb7d37f606e31f50ad6f85bc3882631ad.

User can't create pages in his personal site.

Michael SaechangJune 8, 2012 at 5:36 PM

Committed on:
Portal 6.1.x CE GIT ID: 8b42370f5da0d0fa7c27748217681d8837fef67a.
Portal 6.2.x GIT ID: 7bd273390bbd828fc90d7016a68e8c7cfeb95701.

Juan GonzalezMay 30, 2012 at 1:21 AM

Related issue:

Fixed

Details

Assignee

Reporter

Labels

Branch Version/s

6.1.x

Backported to Branch

Committed

Fix Priority

3

Git Pull Request

Components

Priority

Zendesk Support

Created May 29, 2012 at 2:45 AM
Updated June 24, 2023 at 3:49 PM
Resolved June 4, 2012 at 10:17 AM
Loading...