Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-34920

When a Bookmark is uploaded, authenticated users can see Add New in Asset Publisher even without the right permission

    Details

      Description

      Description
      If you upload a Bookmark, then add the Asset Publisher portlet to a page, authenticated users will see an Add New button even if they don't have the permission to add it.
      And since the user doesn't have permission to add those assets, if they click on Add New -> Bookmark Entry, they'll receive a permission error.

      The Add New button shouldn't even show up in the first place.

      Steps to Reproduce
      1. Create a user, User A
      2. Add him as a Member of any Site. In my case, it was the default Liferay Site.
      3. On the Site Page, add an Asset Publisher portlet.
      4. Using another browser, login as User A, and go to that page with the Asset Publisher portlet.
      You'll see nothing, which is fine.
      5. As Test Test, add a Web Content (via Asset publisher if you want).
      User A can see it, but will not have access to edit it. This is normal.
      6. As Test Test, add a Calendar event (via Asset publisher if you want).
      User A can see it, but will not have access to edit it. This is normal.
      7. As Test Test, add a Bookmark (via Asset publisher if you want).
      User A can see it, and now, if he clicks on Add New, he now has the choice to add Bookmarks. But when he clicks on it, it also tells him he has no access!

      This seems related to LPS-29296, as that ticket was essentially the same issue, but with Documents.

        Attachments

          Issue Links

            Activity

              People

              • Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:
                  Days since last comment:
                  6 years, 40 weeks, 1 day ago

                  Packages

                  Version Package
                  6.1.30 EE GA3
                  6.2.0 CE M6