-
Notifications
You must be signed in to change notification settings - Fork 481
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Permissions: If attempt to access unpublished dv as registered user without perms, get log in page. #1057
Comments
This is because on build guest still had a role with the "discover" permission. I went ahead and removd that role assignment and it's all set. |
This is not the guest issue, it is a registered user, sending back. |
Assigning to @eaquigley do decide what the best workflow should be. Right now the logic on dataverse and datset check if you have access and if not send you to login. This is perfect if a guest user, but what should it do if you are registered. Still go here so you can log in as someone else? Or should it go somewhere else, saying you don't have access. (and then what options should it present) |
instead of taking the user to the log in page, for 4.0, i'd like this to take them to the 404 page. |
To differentiate between a url that yields an object that is not found and one that is found, but the session user does not have permission to view, I have added a 403.xhtml page |
Added redirect logic for Dataverse and Dataset pages |
OK, works for logged in user without sufficient perms, for user who is not logged in, they go to the log in page. Closing. |
I attempted to paste the url for root dv into the browser when logged in as a user without perms:
https://dvn-build.hmdc.harvard.edu/dataverse.xhtml?id=287
It sent me to the log in page even though the navbar showed that I was still logged in.
The text was updated successfully, but these errors were encountered: