Details
-
Bug
-
Status: Needs priority
-
Normal
-
Resolution: Unresolved
-
14.5.0
-
None
-
None
-
Flagged
-
Orion
-
Puma Sprint 266, Puma sprint 272, Puma Sprint 273, Puma Sprint 274, Puma sprint 275
Description
A readonly user, with these userroles:
- xm.cms.user - Required to login and use the CMS application
- xm.channel.viewer - Allows viewing channels through role channel-viewer; implies xm.webfiles.reader
- xm.content.viewer - Allows viewing content through role readonly
can open the Experience Manager and see preview channels.
Expected: blue +Page button is not visible/enabled
Actual: blue +Page button is visible and enabled, user can try to create an XPage (which fails later on).
Easily reproducible onĀ https://cms.demo.onehippo.com
Attachments
Issue Links
- relates to
-
CMS-14675 XPages: as 'viewer' user, call to getActionsAndStates returns 403 due to privilege mismatch
- Needs priority