Details
-
Type:
Bug
-
Status:
Verified
-
Priority:
Minor
-
Resolution: Unresolved
-
Affects Version/s: 6.1.1 CE GA2, 6.1.10 EE GA1, 6.2.0 CE M2
-
Fix Version/s: None
-
Component/s: Social Networking, Social Networking > Activities
-
Labels:None
-
Environment:Tomcat 7.0 + MySQL 5. 6.1.x GIT ID: 6d6b8814da7c7295ed4cab8420e070793361f856.
Tomcat 7.0 + MySQL 5. 6.2.x GIT ID: 71ce8e940ae12bae24e2a5e14cf3f836bb291915.
-
Fix Priority:3
-
Similar Issues:
Description
Content that should not be displayed in Members' Activities is listed anyway.
How to reproduce :
1. Create 2 (regular) roles : "Big" and "Little"
2. Create one user ("BigUser") with "Big" role and another ("LittleUser") with "Little" role
3. Create a regular Organization named "Org" and add "BigUser" and "LittleUser" as members
4. Create a "Wiki" page in "Org" with "view" permission only for "Big" role
5. Create an "Activities" page in "Org" with "view" permission for "Organization Members" role
6. Add a "wiki" portlet to "Wiki" page and an "Members' Activities" portlet on "Activities"
7. Add a wiki page with default permissions ("Viewable by Organization Members")
===> A new line appears on "Activities"
8. Connect with "LittleUser" and go to "Activities"
9. Click on the link to the new wiki page
===> An error appears : you can't access the wiki page
10. Connect back with your admin user
11. Change permissions to "Wiki" page so that "Little" role can view it
12. Change Organization's Wiki "Main" node permissions so that only "Big" role can view it
13. Connect with "LittleUser" and go to "Activities"
14. Click on the link to the new wiki page
===> An error appears : you can't access the wiki node
Note that I made this exemple for a wiki but it "works" with other contents too (Calendar events, for exemple). I tried on an organization, but a Community can have the problem too.
The problem is here with users' private pages, too.
Regards,
Pierre

Hi Pierre Morin,
Thanks for the report,I have some questions,first,you use "Members' Activities" portlet on "Activities" page,not "Activities" portlet? "Members' Activities" portlet only display member user's,not administrator's.Second,at beginning you add Wiki page view permission only for "Big" role,so if you sign in with little user,I think of course you couldn't see the wiki page.because little user didn't have that permission,and then at step 12 you change permissions to "Wiki" page so that "Little" role can view it,but at the viki page,you change the permissions so that only "Big" role can view it,I think little user of course couldn't see it.If at the viki page you give the permission that little role also can view it,little user can see the viki page.If I understand anything wrong,please reply me,thanks.I will close this ticket first.