Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-54433

Private page of type "Link to URL" is publicly available

Details

    Description

      Guest users accessing directly a private site page of type "Link to URL" are able to overcome portal authentication and are redirected to the linked URL.

      Steps to reproduce:

      1. Add a private page to your site with Name="URLPage", Type="Link to URL" and URL="http://www.google.com";
      2. Sign out;
      3. Enter the URL http://localhost:8080/group/guest/urlpage;

      Expected result:

      As the user is not authenticated, he should not be able to access this portal private resource and should be redirected to the login page.

      Actual result:

      Even though the defined page is private, guest user accesses it and redirection happens.

      Attachments

        Issue Links

          Activity

            People

              beck.liu Beck Liu
              filipe.afonso Filipe Afonso
              Kiyoshi Lee Kiyoshi Lee
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:
                7 years, 40 weeks ago

                Packages

                  Version Package
                  6.2.4 CE GA5
                  6.2.X EE
                  7.0.0 M5