Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-27893

ReadOnly user can add directories as Target Document without Write permissions to them

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: ADDONS_10.10
    • Component/s: Aspera Connector
    • Team:
      NOS
    • Sprint:
      NOS 11.1.16 - 2019-08 2, NOS 11.1.17 - 2019-09 1

      Description

      After adding read only permissions to a user in one domain, when we login with that user we can use the Nuxeo Upload with Aspera and upload a file to webui and give permissions to other users to see that document

      How to reproduce:

      • With Admin create a user and give Read Only permission in the Domain to it
      • login with Read Only user
      • go to Nuxeo Upload with Aspera
      • upload a document adding a workspace in the Domain as a Target Document(error - with Read Permissions you shouldn't be able to choose directories besides your own userWorkspace)
      • edit the rest of the metadata
      • complete transfer - operation fails with message:
        Failed to invoke operation FileManager.Import, Not enough rights to create folder --->(should fail early)

        Attachments

          Activity

            People

            • Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 5 hours
                5h