Uploaded image for project: 'Magnolia'
  1. Magnolia
  2. MAGNOLIA-5537

DefaultACLBasedPermissions do not account for JCR's reordering permission

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Critical
    • Resolution: Fixed
    • Affects Version/s: 5.2
    • Fix Version/s: 5.2.1
    • Component/s: core, security
    • Labels:
      None
    • Magnolia Release:
      5.2.1

      Description

      As diagnosed in MGNLUI-2510:

      When setting a subtree in pages to read-only, one can still reorder nodes relatively to its siblings.

      Turns out ordering logic in JCR is relying on the Permission.MODIFY_CHILD_NODE_COLLECTION JCR permission, which is currently not mapped to our Permissions in the DefaultACLBasedPermissions class.

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              mgeljic Mikaël Geljić
              Reporter:
              mgeljic Mikaël Geljić
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: