Affects Version/s: Master
Component/s: Pages > Page Administration
With the re-added feature to Mark Pages as a "Home Page" we may have forgot to reset its permission properties. Currently, users with only view permissions for Pages (and Pages Administration) can mark pages as the default Home Page for the Site. The fact that they still can't edit or configure the page reinforces that this is probably a bug. In fact, it is highly likely that 'mark as home page' option will always be present, i.e. in staging live site too
Steps to Reproduce
- Create a User with only Page View Permissions and the ability to access the Pages Admin from Site Admin
- Impersonate / Log in as the user
- Assert that Site Pages can be viewed and not Editable / Configurable (If this assertion fails, retry the steps)
- Try to mark page as "Home Page"
You can't mark page as "Home Page"
You can mark page as "Home Page"
Reproduced on Tomcat 9.0.6 + MySQL 5.7
Portal master GIT ID: 3e0ccd1533b5e753016c3444ba6b2c38a56e105e