-
Notifications
You must be signed in to change notification settings - Fork 106
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Groups with access to single subsite can create draft pages on other subsites #434
Comments
Almost certainly the same problem as reported here: #358 |
This issue didn't involve sub-groups or roles |
Yeah - but the problem uncovered in that issue highlighted some pretty major flaws in how subsites handles permission validation. |
Thanks for the update. Any idea if/when this will be looked at? This is a little bit concerning, especially as this is offered on the CWP platform. |
It has been looked at in the past but is a pretty nuanced problem (see #388). I'm not sure when it will be looked at again. I understand that it's part of the CWP product but we have over 90 modules that we support as part of CWP so it can be difficult. |
Maybe you should reduce the number of modules offered if you do not have the capacity to support them. |
Thank you for the report. If you are unable to assist, then this is a question not of capacity, but of priority. |
This seems to be an issue that I cannot resolve through the Groups and Roles interface and seems to be a bug with how Subsites works.
I have a basic site (SS4.4) running subsites with the following:
main site
I create a group called Wellington and one called Hutt within each subsite and provide them both with the following permissions:
I then set the permissions on Wellington and Hutt so that they can only access a certain subsite (Wellington group can only access Wellington Subsite etc)
I then visit the Wellington sites URL and log in as the Hutt Member and I can view the admin section of the site with the following section options:
I can click into Pages and view the sitetree for a site that I shouldn't be able to access. I can also use the Add new button and add draft pages to the site that the user should not be able to access.
If I set the permissions for a group to only be able to access a single sub site then I wouldn't expect that user to be able to view the sitetree or add draft pages to a sitetree on another subsite.
The text was updated successfully, but these errors were encountered: