Dan Haywood created ISIS-895:
--------------------------------
Summary: HomePage should honour authorization rules.
Key: ISIS-895
URL: https://issues.apache.org/jira/browse/ISIS-895
Project: Isis
Issue Type: Improvement
Components: Core, Viewer: Wicket
Affects Versions: core-1.6.0, viewer-wicket-1.6.0
Reporter: Dan Haywood
Assignee: Dan Haywood
Priority: Minor
Fix For: viewer-wicket-1.7.0, core-1.7.0
So, if a user doesn't have permission (the home page action isn't visible
and/or usable) then it shouldn't be invoked, and instead simply show the
welcome messages.
However, this ticket does NOT require that the system checks that the user has
permissions for the resultant object invoked from the home page action (a
dashboard or whatever); rather the expectation is that the this the permissions
be set-up correctly along with the user's permission to the home page action.
If the user doesn't have permission to the resultant object, then the usual
behaviour should occur, ie to show the error page.
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)