Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-6003

incorrect security check in export restlet when Anonymous is enabled

    XMLWordPrintable

    Details

      Description

      Once authenticated, users that have no rights to access the exported root document get access to the content.

      This can be put easily in evidence by

      • creating a document note using the administrator account
      • exporting the document note using an anonymous access

        Attachments

          Activity

            People

            • Assignee:
              slacoin Stéphane Lacoin
              Reporter:
              slacoin Stéphane Lacoin
              Participants:
            • Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: