New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Read publish permission is not enough to read binary fields #111

Closed
bernhardriegler opened this Issue Aug 28, 2017 · 1 comment

Comments

Projects
None yet
2 participants
@bernhardriegler
Contributor

bernhardriegler commented Aug 28, 2017

Gentics Mesh Version, operating system, or hardware.

  • v0.9.27

Operating System

  • Linux
  • MacOSX
  • Windows

JVM

  • Oracle JDK 1.8.0_100
  • Open JDK 1.8.0_100

Problem

A user with a role that has permissions to "read published" nodes will get a "Missing permissions..." response, when trying to load binary fields from a node via the download endpoint.

{meshAPIRoot}/api/v1/{projectName}/nodes/{nodeUuid}/binary/{fieldName}

When the "Read" permission is granted, the user can access the file.

Reproducer

Expected behaviour and actual behaviour

The permission "read published" should suffice for a user/role to access all fields of a node.

@bernhardriegler bernhardriegler added the bug label Aug 28, 2017

@Jotschi

This comment has been minimized.

Member

Jotschi commented Aug 28, 2017

I have reproduced the issue. Thanks for reporting it.

@Jotschi Jotschi closed this in ebb6b50 Aug 28, 2017

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment