Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-82501

User has option to Delete Kaleo Form filled in form without permission

Details

    Description

      Prerequisites:

      1. Create new basic user
      2. Set User role permissions as in gif

       
      Steps:

      1. As admin, navigate to Content -> Kaleo Forms Admin
      2. Create new Form
      3. View created Form
      4. Add new form, fill in some fields, save it
      5. Go back to Kaleo Forms Admin
      6. From action menu, select Permissions
      7. Set Permission for user to View Form (optionally also Delete, because it doesn't make any difference at all)
      8. Login as user, access Kaleo Forms Admin
      9. Select View from action menu of Form
      10. Select Delete from action menu of filled in specific form
      2018-06-15 09:29:16.823 ERROR [http-nio-8080-exec-1][PortletServlet:112] javax.portlet.PortletException: com.liferay.portal.kernel.security.auth.PrincipalException$MustHavePermission: User 36215 must have DELETE permission for com.liferay.dynamic.data.lists.model.DDLRecordSet 36112
      javax.portlet.PortletException: com.liferay.portal.kernel.security.auth.PrincipalException$MustHavePermission: User 36215 must have DELETE permission for com.liferay.dynamic.data.lists.model.DDLRecordSet 36112
      

      Expected result: There is no option for user to delete filled in form / there is error message displayed / user can delete form
      Actual result: Page is not displayed correctly, no error message, filled in form is not deleted

      Reproducible:

      • CentOS, MySQL 5.6, Tomcat 9.0.6, FF 60
      • DXP 7.1-b3-20180611120257571

      Fix priority: S3 + L3 = 3

      Attachments

        Activity

          People

            brian.chan Brian Chan
            petr.matej Petr Matej (Inactive)
            Kiyoshi Lee Kiyoshi Lee
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:
              4 years ago

              Packages

                Version Package
                7.2.10 DXP FP1
                7.2.X
                Master