Uploaded image for project: 'CMS'
  1. CMS
  2. CMS-7197

Wrong access checking on a filtered contents service with private contents

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Major Major
    • 3.7.4, 3.8
    • None
    • None
    • None

      I have the following page access configuration :

      • Page A (restricted to user1, user2)
        • Page A1 (restricted to user2, user3)
        • Page A2 (restricted to user1, user2)

      The page A contains a filtered contents service.

      When I access to page A with user1 on FO, I can see the contents of page A1 and page A2.
      If I click on content of page A1, I have a AccessDeniedException
      The content of page A1 should not appear on page A

          [CMS-7197] Wrong access checking on a filtered contents service with private contents

          I have the following page access configuration :

          • Page A (restricted to any connected users)
            • Page A1 (user1 excluded)
            • Page A2 (no specific restriction)

          The page A contains a filtered contents service sur "page access" limitation.

          When I access to page A with user1 on FO, I can see the contents of page A1 and page A2.
          If I click on content of page A1, I have a AccessDeniedException
          The content of page A1 should not appear on page A.

          Laurence Aumeunier added a comment - I have the following page access configuration : Page A (restricted to any connected users) Page A1 (user1 excluded) Page A2 (no specific restriction) The page A contains a filtered contents service sur "page access" limitation. When I access to page A with user1 on FO, I can see the contents of page A1 and page A2. If I click on content of page A1, I have a AccessDeniedException The content of page A1 should not appear on page A.

          Furthermore, the excluded users/groups are not take into account

          Laurence Aumeunier added a comment - Furthermore, the excluded users/groups are not take into account

            Unassigned Unassigned
            laurence Laurence Aumeunier
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: