Uploaded image for project: 'Magnolia'
  1. Magnolia
  2. MAGNOLIA-5537

DefaultACLBasedPermissions do not account for JCR's reordering permission

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Critical
    • 5.2.1
    • 5.2
    • core, security
    • None

    Description

      As diagnosed in MGNLUI-2510:

      When setting a subtree in pages to read-only, one can still reorder nodes relatively to its siblings.

      Turns out ordering logic in JCR is relying on the Permission.MODIFY_CHILD_NODE_COLLECTION JCR permission, which is currently not mapped to our Permissions in the DefaultACLBasedPermissions class.

      Checklists

        Acceptance criteria

        Attachments

          Issue Links

            Activity

              People

                mgeljic Mikaël Geljić
                mgeljic Mikaël Geljić
                Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                  Created:
                  Updated:
                  Resolved:

                  Checklists

                    Bug DoR
                    Task DoD