Uploaded image for project: '[Read Only] - Hippo Site Toolkit 2'
  1. [Read Only] - Hippo Site Toolkit 2
  2. HSTTWO-3765

Return canManageChanges and canDeleteChannel in /composermode call based on privileges of current user

    XMLWordPrintable

Details

    • New Feature
    • Status: Closed
    • Normal
    • Resolution: Fixed
    • 4.1.0
    • 4.1.0
    • None
    • None
    • 0.5
    • Platform Sprint 136, Tiger Sprint 137

    Description

      The 'canManageChanges' permissions used to be checked in Wicket code of the channel manager (in ChannelEditor.java). Since HSTTWO-3728 that logic got removed, and instead the /composermode REST call now returns those permissions. However, both canManageChanges and canDeleteChannel do not yet check the actual permissions of the current user. That should be fixed in this issue.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              mdenburger Mathijs den Burger (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: