Uploaded image for project: 'PUBLIC - Liferay Social Office Community Edition'
  1. PUBLIC - Liferay Social Office Community Edition
  2. SOS-1796

Super Admins are able to access pages of Private and Private Restricted Sites that they do not own by way of activities



      Here are the steps to reproduce:

      1. Add an SO user and add the user as a connection
      2. Sign out and sign in as the new user
      3. Have the new user add a private site or private restricted site; add a calendar event to the site
      4. Sign out and sign in as Joe Bloggs
      5. Go to Activities

      Expected Result:
      The activity from the site should NOT be visible

      Actual Result:
      The user's calendar event will be visible along with a link to the site. Clicking on the link to the site will also take Joe Bloggs to a full view of the site pages

      This does not occur if the steps are taking place between regular users. This only occurs with the super admin and a regular user.




            • Votes:
              0 Vote for this issue
              0 Start watching this issue


              • Created:
                Days since last comment:
                6 years, 46 weeks, 5 days ago


                Version Package
                2.1.X CE
                2.1.X EE