Uploaded image for project: '[Read Only] - Hippo Repository'
  1. [Read Only] - Hippo Repository
  2. REPO-2111

authors can invoke publishBranch, reintegrate and depublishBranch workflow actions

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Normal
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 5.6.0
    • Component/s: None
    • Labels:
      None
    • Similar issues:
    • Story Points:
      2
    • Processed by team:
      Turing
    • Sprint:
      Turing Sprint 191

      Description

      Authors are not allowed to execute publish/depublish or reintegrate workflow actions, but currently they are allowed to execute publishBranch and depublishBranch and reintegrate.

      Although authors will never call these actions via the UI (we use publish and depublish hints for the buttons) it is still an security issue. Developers could for instance implement custom workflow actions that would call these workflow actions.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                Unassigned
                Reporter:
                meggermont Michiel Eggermont
              • Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: