Affects Version/s: 7.3 FP1, 7.3 FP2
Fix Version/s: None
Component/s: Shopping Experience
Severity of Issue:Major
It doesn't appear that the permissions on a product attachment are being checked before displaying attachments or allowing downloads.
Steps to Reproduce
1. Apply Minium Demo Pack and re-index
2. Log in as [email protected]
3. Upload a document to the Global scope and set permissions so only Owner has access to the document
4. Navigate to Product Catalog -> Brake Pad -> Product Media
5. Add new attachment and select the document uploaded in step 3
6. Publish Product and log out
7. Log in as [email protected] and navigate to Brake Pad.
As Mike, who only has the 'User' and 'Buyer' roles, the document should not appear in the list of product attachments
As Mike, the document is visible and downloadable.