[MAGNOLIA-4344] Users other than superuser can not view versions Created: 22/Mar/12  Updated: 02/Apr/12  Resolved: 29/Mar/12

Status: Closed
Project: Magnolia
Component/s: activation, security, workflow
Affects Version/s: 4.5.1
Fix Version/s: 4.5.2

Type: Bug Priority: Critical
Reporter: Matt Dertinger Assignee: Jan Haderka
Resolution: Fixed Votes: 0
Labels: security, versioning, workflow
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Attachments: PNG File screenshot-systemRepositories.png    
Template:
Acceptance criteria:
Empty
Task DoD:
[ ]* Doc/release notes changes? Comment present?
[ ]* Downstream builds green?
[ ]* Solution information and context easily available?
[ ]* Tests
[ ]* FixVersion filled and not yet released
[ ]  Architecture Decision Record (ADR)
Bug DoR:
[ ]* Steps to reproduce, expected, and actual results filled
[ ]* Affected version filled
Date of First Response:

 Description   

Hi,

I just came across this issue. It seems that users other than the superuser can not view version history from within AdminCentral.

Steps to reproduce:

  1. Log into http://demoauthor.magnolia-cms.com as superuser
  2. Go to Documents/demo-project/img/logos
  3. Right click on magnolia-logo and choose Delete, then click Ok in the dialog box that appears
  4. Right click on the magnolia-logo again, and choose Versions
  5. In the Versions dialog that opens, you should see a version that you can restore to. Close the window without restoring.
  6. Log out as superuser, then log in as eric
  7. Go to Documents/demo-project/img/logos
  8. Right click on magnolia-logo, and choose Versions
  9. Note that there is no version information displayed, and eric can't restore a version

The same thing occurs when activating content. Users other than superuser aren't able to view Versions.

Let me know if you have any other questions.

Cheers,
Matt



 Comments   
Comment by Magnolia International [ 23/Mar/12 ]

I tried adding read-only for /* the sample user, but that didn't help either.

Comment by Matt Dertinger [ 26/Mar/12 ]

Hi,

While working on a completely unrelated issue, I came across some potentially suspect configuration that might be related to this issue. The following two content nodes only contain a description node data with an empty value (see attached screenshot):

/config/modules/adminInterface/config/securityConfiguration/systemRepositories/mgnlSystem
/config/modules/adminInterface/config/securityConfiguration/systemRepositories/mgnlVersion

Cheers,
Matt

Generated at Mon Feb 12 03:54:53 CET 2024 using Jira 9.4.2#940002-sha1:46d1a51de284217efdcb32434eab47a99af2938b.