Uploaded image for project: 'PUBLIC - Liferay Social Office Community Edition'
  1. PUBLIC - Liferay Social Office Community Edition
  2. SOS-1796

Super Admins are able to access pages of Private and Private Restricted Sites that they do not own by way of activities

    Details

      Description

      Here are the steps to reproduce:

      1. Add an SO user and add the user as a connection
      2. Sign out and sign in as the new user
      3. Have the new user add a private site or private restricted site; add a calendar event to the site
      4. Sign out and sign in as Joe Bloggs
      5. Go to Activities

      Expected Result:
      The activity from the site should NOT be visible

      Actual Result:
      The user's calendar event will be visible along with a link to the site. Clicking on the link to the site will also take Joe Bloggs to a full view of the site pages

      This does not occur if the steps are taking place between regular users. This only occurs with the super admin and a regular user.

        Attachments

          Activity

            People

            • Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:
                Days since last comment:
                6 years, 11 weeks, 2 days ago

                Packages

                Version Package
                2.1.X CE
                2.1.X EE