Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-62949

User with permissions for Site Admin menu can access message boards

    Details

      Description

      Reproduced on:
      Tomcat 8.0.30 + MySQL 5.6.25. Portal master GIT ID: 6aee08e4cb953dfa2aa95a2364b6f074849ebaf4.

      Steps to Reproduce:

      1. Use clean database (fixed in LPS-63605)
      2. Add new role
      3. Define Permissions
      4. Add permission for Site Administration > Content > Forms > Access in Site Administration
      5. Save role
      6. Add new user with new role and remove power user role
      7. Login to new user
      8. Go to Liferay > Content in the product menu

      Expected Result:
      User only has access to Forms in Site Admin.

      Actual Result:
      User has access to Message Boards in Site Admin without permissions. "Site Settings > Site: View Site Administration Menu" grants this.


      CVSS Base Score: 6
      CVSS Temporal Score: 6
      CVSS Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:P/E:H/RL:U/RC:C)
      

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              ian.song Ian Song (Inactive)
              Reporter:
              victor.ware Victor Ware
              Participants of an Issue:
              Recent user:
              Esther Sanz
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:
                Days since last comment:
                5 years, 41 weeks, 2 days ago

                  Packages

                  Version Package
                  7.0.0 Beta 8