Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Some Item edit pages are accessible by anonymous users #2609

Closed
ybnd opened this issue Nov 9, 2023 · 1 comment · Fixed by #2632
Closed

Some Item edit pages are accessible by anonymous users #2609

ybnd opened this issue Nov 9, 2023 · 1 comment · Fixed by #2632
Assignees
Labels
authorization related to authorization, permissions or groups bug high priority ux User Experience related works
Milestone

Comments

@ybnd
Copy link
Member

ybnd commented Nov 9, 2023

Describe the bug
A few of the item/*/edit/* pages do not seem to have properly configured guards.
As far as I see all of these pages are non-functional, so the impact of this bug is minimal.

It's likely that there are other similar cases -- would be good to look for more examples and address them in one go.

To Reproduce
Steps to reproduce the behavior:

  1. Go to any of the following pages without logging in to DSpace:
  2. The actual page will render, but will not be usable (e.g. due to missing data, failing REST requests)

Expected behavior
Users without the necessary authorizations (and especially anonymous users) should not have access to administrator pages.
Instead, they should be redirected to the login page, or be shown a 403 page.

Related work
#2247

@ybnd ybnd added bug needs triage New issue needs triage and/or scheduling authorization related to authorization, permissions or groups ux User Experience related works labels Nov 9, 2023
@tdonohue
Copy link
Member

tdonohue commented Nov 9, 2023

@ybnd : If you (or your team) happen to have any time in the next few days, it would be good to patch these quickly for 7.6.1 (which I hope we get out next week sometime). I agree the pages don't seem to be usable at all, but it'd be good to fix them nonetheless.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
authorization related to authorization, permissions or groups bug high priority ux User Experience related works
Projects
Development

Successfully merging a pull request may close this issue.

3 participants