Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-113178

Prevent a web content author that looses his membership of a site from still being able to edit all the web content articles he previously authored in the site

    Details

      Description

      In Liferay 6.2 EE and DXP 7.2, we noticed that after a web content author looses his membership of a site, he can still edit all the web content that he previously authored.

      Support confirmed Liferay worked as intended, that this was not a bug and that there was no portal property to prevent this from occurring.

      There are 2 workarounds but they both require to perform an operation on each of the related web content articles:

      1) A site administrator should republish a new version of each of these web content articles.

      2) As site administrator should remove the "Permission" and "Update" permissions for the Owner of each of these web content articles

      Steps to reproduce the behaviour:

      • Sign in as an administrator
      • Add a user and change his password
      • Add an "Editor" site role with the following permissions:
        Site Pages > Page: Update
        Web Content > Web Content: Add Web Content
        Web Content Display: Configuration
      • Add the new user as a member of the default public site (site membership)
      • Assign the "Editor" site role to the user in this site
      • Sign in as the user
      • Add a web content display portlet on the home page
      • Add a new web content in this portlet
      • Put some content in the web content and publish it
      • Sign in as an administrator
      • Remove membership of the user from the default site
      • Sign in as the user

      Expected result:
      On the home page, the user cannot edit the web content he authored previously since he is not a member of the site anymore.

      Actual result:
      The user can still edit the web content he authored previously on the home page (the edit button is displayed in the web content display portlet and the user is able to update the web content and publish it).

       

      A configurable property to prevent this behaviour from occurring would be welcome.

      Thanks.

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              tarik.demnati Tarik Demnati
              Reporter:
              Jean-Michel.FRIPPIAT Jean-Michel Frippiat
              Votes:
              2 Vote for this issue
              Watchers:
              1 Start watching this issue

                Dates

                Created:
                Updated:

                  Packages

                  Version Package