Uploaded image for project: 'Magnolia'
  1. Magnolia
  2. MAGNOLIA-1011

MgnlContext should never fallback to SystemContext

    XMLWordPrintable

Details

    • Task
    • Resolution: Fixed
    • Critical
    • 3.0 RC4
    • 3.0 RC2
    • core
    • None

    Description

      Its a breach of security if we set System context if nothing is set, A simple example would be if you call a JSP from within your template you will have full access without even realizing.

      If its a problem that workflow engine cannot set proper permissions, we can set SystemContext there instead of leaving this security hole.

      Checklists

        Acceptance criteria

        Attachments

          Activity

            People

              scharles Sameer Charles
              scharles Sameer Charles
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Checklists

                  Task DoR