Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-32533

Do not send a notification to a user who does not have the Read permission on the document

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Won't Fix
    • Affects Version/s: 2021.0
    • Fix Version/s: 2021.x, 2023.x
    • Component/s: Notifications
    • Release Notes Summary:
       notification.check.read.permission conf property can be set to true to achieve this
    • Backlog priority:
      800
    • Sprint:
      nxplatform #114
    • Story Points:
      3

      Description

      Steps to reproduce:

      1. Create a user jane who belongs to the "members" group
      2. Create a Workspace named "WS Test" under Default domain > Workspaces
      3. Create a Workspace named "Private" under Default domain > Workspaces > WS Test
      4. Block rights inheritance on the Private workspace
      5. Log in as "jane"
      6. Navigate to Default domain > Workspaces > WS Test
      7. Click on the "Notify me" button
      8. Log in as "Administrator"
      9. Create a Note under Default domain > Workspaces > WS Test > Private
      10. Observe that jane has received a notification for the newly created note
      11. If jane is logged in and clicks on the link to the document in the email, she'll received an error "403 Permission Denied Privilege 'Read' is not granted to 'jane'"

      Expected behavior: the notification should not be sent to jane because she does not have the sufficient permission to see the document

        Attachments

          Issue Links

            Activity

              People

              • Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: