Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-65108

Document Library folder permission is not inherited to basic document

    Details

    • Type: Bug
    • Status: Closed
    • Resolution: Won't Fix
    • Affects Version/s: 6.2.10 EE GA1, 6.2.X EE, 7.0.1 CE GA2
    • Fix Version/s: None
    • Component/s: DM, Security Vulnerability
    • Labels:
      None
    • Fix Priority:
      4

      Description

      Description
      The default portal property "permissions.view.dynamic.inheritance=true" should cause the portal server to check "the view permission on the document's folder and all its parent folders." (quote from portal properties)

      However, that does not work.

      To reproduce:
      1. Login as administrator
      2. Create folder "files" in document library and revoke all permissions from that folder except the owner permissions
      3. Create subfolder "images" in folder "files" with guest view and access permissions
      4. Add some file to folder "images" with guest view permission
      5. Place search portlet on home page
      6. Logout
      7. Search for the filename of the uploaded file

      Result: The search returns the file entry and the file can be downloaded.
      Expected: The search should return no results and the file entry should not be accessible as the guest user does not have access or view permission on the top folders

      The reason of this is while the permission check for the view action coalesces to the parent folder, the check for access action does not.

        Attachments

          Activity

            People

            • Assignee:
              sergio.gonzalez Sergio Gonzalez (Inactive)
              Reporter:
              istvan.dezsi Istvan Dezsi
              Participants of an Issue:
              Recent user:
              Austin Bennett (Inactive)
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:
                Days since last comment:
                3 years, 5 weeks, 2 days ago

                Packages

                Version Package