[
https://jira.duraspace.org/browse/DS-1491?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=27717#comment-27717
]
Bram Luyten (@mire) commented on DS-1491:
-----------------------------------------
I was not able to reproduce this using the demo.dspace.org setup.
What I did:
Browser nr1:
- visit http://demo.dspace.org/xmlui/handle/10673/482
- login as [email protected]
- copied the edit this item link
http://demo.dspace.org/xmlui/admin/item?itemID=662
Browser nr2 (different browser, different session)
- logged in as submitter [email protected] , with submission rights
to the collection in which the item was contained
- went to the page http://demo.dspace.org/xmlui/handle/10673/482
- went to the link, copied from the other browser to edit
http://demo.dspace.org/xmlui/admin/item?itemID=662
- immediately got an insufficient privileges message
Insufficient privileges
Your account has insufficient privileges to perform the requested action. If
you feel this is an error or have questions about your privileges, please
contact the site's system administrators.
Are you sure the account you are using does not have any collection admin
rights? Because it's very surprising that they get to see this edit dialog in
the first place.
> COLLECTION_*_SUBMIT Role has permissions to edit all metadata after item is
> published
> -------------------------------------------------------------------------------------
>
> Key: DS-1491
> URL: https://jira.duraspace.org/browse/DS-1491
> Project: DSpace
> Issue Type: Bug
> Components: XMLUI
> Affects Versions: 3.0
> Reporter: Michael Hicke
> Priority: Critical
> Labels: permissions
> Attachments: dspace_bug2.doc
>
>
> Hello,
> we implemented a workflow where submitters submit items, which are released
> by reviewers.
> Submitters have only a COLLECTION_*_SUBMIT role.
> However, the submitters can edit all metadata of all released items of this
> collection after the item is published.
> This may be a severe bug. See screenshots attached.
> Please tell us if you like to have access to our system.
> Best regards
> Michael
--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira
------------------------------------------------------------------------------
Free Next-Gen Firewall Hardware Offer
Buy your Sophos next-gen firewall before the end March 2013
and get the hardware for free! Learn more.
http://p.sf.net/sfu/sophos-d2d-feb
_______________________________________________
Dspace-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/dspace-devel