Issue (View Online)

Key: NXP-1385
Issue Type: Bug Bug
Status: Open Open
Priority: Critical Critical
Assignee: Thierry Delprat
Reporter: Pascal Vuylsteker
Environment: MacOSX 10.4 / Firefox / Safari

Operations

View all
View comments
View history
Access to document that should not be accessible through the REST URL : Error 500 after 2nd identification 
Updated: 27/07/07 13:30   Created: 27/07/07 13:22  

The following issue has been updated.

Updater: Pascal Vuylsteker
Date: 27/07/07 13:30
Comment:
Tout en étant identifié comme un second utilisateur (teiva) sans droit particulier

Field Original Value New Value
Change By Pascal Vuylsteker on 27/07/07 13:30
Attachment Demande d'identification coomplémentaire.jpg

Project: Nuxeo Enterprise Platform 5
Components: Security
Affects Versions: 5.1 M3
Attachments: bugNuxeoError500.txt, Contenu du repertoire privé.jpg, Crash Tomcat !.jpg, Demande d'identification coomplémentaire.jpg, Document dans le repertoire privé.jpg, Droit d'acces au repertoire privé.jpg

 Description   
As a simple user, I created a directory for which I canceled any inherited access right. This folder content should only be accessible by a single user (except in the well described context of a workflow...).
Then I added a document in that folder.
I went to the summary page of that document
I copied th URL of that page.
I log out.
I log in as a different user.
I paste de previousely copied URL ... (http://localhost:8080/nuxeo/nxdoc/demo/5301558e-65b9-4a3c-b6c8-a80b66b56181/view_documents/default/?conversationId=0NXMAIN&conversationIsLongRunningtrue
)
I am asked a new identification (that is good), but if I tried to enter the inital user id (the owner of the folder), I got back a really inelegant Error 500 page (See an extract at the end).


"HTTP Status 500 -

type Exception report

message

description The server encountered an internal error () that prevented it from fulfilling this request.

exception

javax.servlet.ServletException: /login.xhtml @16,76 value="#{userDTO.username}": Target Unreachable, identifier 'userDTO' resolved to null"

This message was automatically generated by Atlassian JIRA Enterprise Edition, Version: 3.10-260 - Bug/feature request.
If you think it was sent incorrectly, contact one of this server's administrators.

_______________________________________________
ECM-tickets mailing list
[email protected]
http://lists.nuxeo.com/mailman/listinfo/ecm-tickets

Reply via email to