jackrabbit-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "angela (JIRA)" <j...@apache.org>
Subject [jira] Commented: (JCR-2363) Node.orderBefore does not check permissions
Date Fri, 23 Oct 2009 15:54:59 GMT

    [ https://issues.apache.org/jira/browse/JCR-2363?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12769270#action_12769270
] 

angela commented on JCR-2363:
-----------------------------

proposed fix: treat the reorder similar to a move and check if the child node to be reordered
can be removed and added.

> Node.orderBefore does not check permissions
> -------------------------------------------
>
>                 Key: JCR-2363
>                 URL: https://issues.apache.org/jira/browse/JCR-2363
>             Project: Jackrabbit Content Repository
>          Issue Type: Bug
>          Components: jackrabbit-core, security
>            Reporter: angela
>            Assignee: angela
>             Fix For: 2.0.0
>
>         Attachments: JCR-2363.patch
>
>
> It seems that Node.orderBefore(String, String) does not check if the editing session
is allowed to modify the parent, neither immediately nor upon saving the transient changes.
> This issue was found by Alexandre Capt. Thanks!

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.


Mime
View raw message