Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-43308

Organization owner can edit the organization members' pages

    Details

    • Fix Priority:
      3

      Description

      1. Create an organization e.g. testorg
      2. Create a user e.g. testuser1
      3. Make testuser1 a member of testorg and assign Organization Owner role to him
      4. Create another user e.g. testuser2
      5. Make testuser2 a member of testorg
      6. Log in and out with both users so their public and private pages get created
      7. Log in with testuser1 and navigate to testuser2's public pages, e.g. http://localhost:8080/web/testuser2/home

      Result: You can edit the page, add/remove/modify portlets, etc.

      8. Navigate to testuser2's private pages, e.g. http://localhost:8080/user/testuser2/home

      Result: Not only you can see the page, but you can also edit it, add/remove/modify portlets, etc.

      The same issue does not exist for Site Owner and Site Member relations.

        Attachments

          Activity

            People

            • Assignee:
              gergely.mathe Gergely Mathe (Inactive)
              Reporter:
              gergely.mathe Gergely Mathe (Inactive)
              Participants of an Issue:
              Recent user:
              Esther Sanz
            • Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:
                Days since last comment:
                5 years, 41 weeks, 1 day ago

                Packages

                Version Package
                6.1.2 CE GA3
                6.1.X EE
                7.0.0 M3