Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-54433

Private page of type "Link to URL" is publicly available

    Details

      Description

      Guest users accessing directly a private site page of type "Link to URL" are able to overcome portal authentication and are redirected to the linked URL.

      Steps to reproduce:

      1. Add a private page to your site with Name="URLPage", Type="Link to URL" and URL="http://www.google.com";
      2. Sign out;
      3. Enter the URL http://localhost:8080/group/guest/urlpage;

      Expected result:

      As the user is not authenticated, he should not be able to access this portal private resource and should be redirected to the login page.

      Actual result:

      Even though the defined page is private, guest user accesses it and redirection happens.

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              beck.liu Beck Liu
              Reporter:
              filipe.afonso Filipe Afonso
              Participants of an Issue:
              Recent user:
              Esther Sanz
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:
                Days since last comment:
                6 years, 37 weeks, 6 days ago

                  Packages

                  Version Package
                  6.2.4 CE GA5
                  6.2.X EE
                  7.0.0 M5