[ 
http://jira.nuxeo.org/browse/NXP-4192?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Radu Darlea updated NXP-4192:
-----------------------------

    Description: 
When a user doesn't have rights to see object document of a relation the 
display is broken.
Steps to reproduce:
- create two users: user1 with read rights on folder F1 and no rights on folder 
F2, and user2 with read-write rights on both folders. 
- log in with user2 and create a document in F1. Next create a relation inside 
this document and a document in F2 (user1 can't see it). 
- log in as user1 and access the previous document contained by F1. Go to 
relations and you will see a link to the document at which was made the 
relation from F2, but with ugly link and clicking on it leads to error.
Possible solutions:
- do not display relations pointing to not visible documents
- display relations pointing to not visible documents but instead of link have 
title or path (NB: to obtain these probably a Unrestricted Runner must be 
called)
- display relations pointing to not visible documents but instead of link have 
some generic message

Which one is best? I would go the first, but it is not my decision.

  was:
When a user doesn't have rights to see object document of a relation the 
display is broken.
Steps to reproduce:
- create two users : first one user1 with read rights, and user2 with write 
rights. 
- log in with user2 and create a document and lock it, after you locked it 
create a relation between the current document and a document that is not 
available for user1. 
- log in as user1 and access the locked document go to relations and you will 
see a link to the document at which was made the relation,that shouldn't be 
vizible for user1, because he doesn't have rights to see that document.


> Fix display of relation when rights are missing
> -----------------------------------------------
>
>                 Key: NXP-4192
>                 URL: http://jira.nuxeo.org/browse/NXP-4192
>             Project: Nuxeo Enterprise Platform
>          Issue Type: Bug
>          Components: Relation Engine
>    Affects Versions: 5.2 GA
>            Reporter: Cristi Mitroi
>            Assignee: Catalin Baican
>             Fix For: 5.3.x
>
>
> When a user doesn't have rights to see object document of a relation the 
> display is broken.
> Steps to reproduce:
> - create two users: user1 with read rights on folder F1 and no rights on 
> folder F2, and user2 with read-write rights on both folders. 
> - log in with user2 and create a document in F1. Next create a relation 
> inside this document and a document in F2 (user1 can't see it). 
> - log in as user1 and access the previous document contained by F1. Go to 
> relations and you will see a link to the document at which was made the 
> relation from F2, but with ugly link and clicking on it leads to error.
> Possible solutions:
> - do not display relations pointing to not visible documents
> - display relations pointing to not visible documents but instead of link 
> have title or path (NB: to obtain these probably a Unrestricted Runner must 
> be called)
> - display relations pointing to not visible documents but instead of link 
> have some generic message
> Which one is best? I would go the first, but it is not my decision.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: 
http://jira.nuxeo.org/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        
_______________________________________________
ECM-tickets mailing list
[email protected]
http://lists.nuxeo.com/mailman/listinfo/ecm-tickets

Reply via email to