Skip to content
This repository has been archived by the owner on Dec 18, 2020. It is now read-only.

User can delete a page with insufficient permissions #777

Open
afroewis opened this issue Dec 19, 2016 · 0 comments
Open

User can delete a page with insufficient permissions #777

afroewis opened this issue Dec 19, 2016 · 0 comments
Labels

Comments

@afroewis
Copy link

Q A
Bug? yes
Feature? no
Sulu Version 1.4.2

Actual Behavior

Two Users:
User_EN: Read permission in de & en, Write permission in EN.
Admin: Any permission anywhere

  1. Admin creates a page in de.
  2. User_EN creates a copy of that page from the ghost page from de in en.
  3. User_EN deletes that page.
  4. This deletes the page in all locales.

Expected Behavior

User_EN should not be able to delete a page in a locale where he does not have the appropriate permission. Since he only has read permission in de, he should not be able to delete the page at all.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

2 participants