Uploaded image for project: 'Magnolia Workflow Module'
  1. Magnolia Workflow Module
  2. MGNLWORKFLOW-179

Any user can launch a workflow regardless of their permissions

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Critical Critical
    • 5.2.1
    • 5.2
    • Base

      As long as a workflow action is available in the UI, there's no security check regarding the grants owned by the current user.
      The basic rule should be "user has Read+Write grants on the workflow workspace AND has at least Read grant on the node they're trying to publish.

        Acceptance criteria

              fgrilli Federico Grilli
              fgrilli Federico Grilli
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved:

                  Bug DoR
                  Task DoD