Uploaded image for project: '[Read Only] - Hippo Repository'
  1. [Read Only] - Hippo Repository
  2. REPO-925

WorkflowManager permission checks fixes

    XMLWordPrintable

Details

    • Bug
    • Status: Closed
    • Low
    • Resolution: Fixed
    • None
    • 2.26.00
    • None
    • None

    Description

      The #getWorkflowDescription(String, Document) incorrectly performs the permissions check using the workflow session instead of the user session.
      In practice this means the check will always succeed.

      For initiating the workflow logging, it uses the user session to check access on the /hippo:log folder, while in this case it actually should use the workflow user session.

      Attachments

        Activity

          People

            jsheriff Junaidh Kadhar Sheriff
            adouma Ate Douma
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: