Dan Haywood created ISIS-895:
--------------------------------

             Summary: HomePage should honour authorization rules.
                 Key: ISIS-895
                 URL: https://issues.apache.org/jira/browse/ISIS-895
             Project: Isis
          Issue Type: Improvement
          Components: Core, Viewer: Wicket
    Affects Versions: core-1.6.0, viewer-wicket-1.6.0
            Reporter: Dan Haywood
            Assignee: Dan Haywood
            Priority: Minor
             Fix For: viewer-wicket-1.7.0, core-1.7.0


So, if a user doesn't have permission (the home page action isn't visible 
and/or usable) then it shouldn't be invoked, and instead simply show the 
welcome messages.

However, this ticket does NOT require that the system checks that the user has 
permissions for the resultant object invoked from the home page action (a 
dashboard or whatever); rather the expectation is that the this the permissions 
be set-up correctly along with the user's permission to the home page action.

If the user doesn't have permission to the resultant object, then the usual 
behaviour should occur, ie to show the error page.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to