Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-59952

Workflow submissions of Site members are visible to every member

    Details

      Description

      When a User navigates to Control Panel > Workflow Submissions, they are able to view the workflow submissions of the other site members as well as withdraw the submissions of those members. The admin should be the only one able to view the submissions of all site members.

      Steps to reproduce:

      1. Set Workflow for Blogs
      2. Add 2 Users (User 1 and User 2)and add them to the Liferay site
      3. Go to Roles > Site Members > Define Permissions
      4. Search Blogs > Click into Content > Blogs
      5. Set these two permissions
        • General Permissions > Access in Site Administration
        • Blog Entries > Add Entry
      6. Save
      7. Sign into User 1 and submit a Blogs entry
      8. Sign into User 2 and submit a Blogs entry
      9. As User 2 go to My Account > My Submissions
      10. Assert you can only see the blogs entry from User 2
      11. Still as User 2 go to Admin > Content > Workflow Submissions
        • Expected Result
          You can still only see the blogs entry submissions from User 2.
        • Actual Result
          You can see both User 2 and User 1 blog entry submissions. User 2 is also able to click the actions icon of User 1 and withdraw their submission.
      12. Log out and log in as User 1
      13. Repeat steps 9-11 for User 1
      14. Log out and log in as Test Test
      15. Go to Admin > Content > Workflow Submissions
      16. Assert you can see the submissions from both User 1 and User 2

      Expected Results
      Even with access to Content > Workflow Submissions, User 1 and User 2 should only see their own submissions. It should have the same behavior as clicking into My Account > My Submissions. Test Test is the only one that should see all of the workflow submissions.

      Actual Result
      User 1 and User 2 are able to see each others' workflow submissions under CP > Workflow Submissions. This allows site members to view and withdraw other members' submissions.

      Reproduced on:
      Tomcat 7.0.62 + MYSQL 5.6.27
      Portal master GIT ID 730ebdf243d1307194cb9a8826fd8234fb7fd3c3

        Attachments

          Activity

            People

            • Assignee:
              clarissa.velazquez Clarissa Velazquez
              Reporter:
              clarissa.velazquez Clarissa Velazquez
              Participants of an Issue:
              Recent user:
              Esther Sanz
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:
                Days since last comment:
                4 years, 31 weeks, 4 days ago

                Packages

                Version Package
                7.0.0 Alpha 2