jackrabbit-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "angela (JIRA)" <j...@apache.org>
Subject [jira] Resolved: (JCR-2418) Read permission on parent node required to access an item's definition
Date Wed, 02 Dec 2009 11:48:20 GMT

     [ https://issues.apache.org/jira/browse/JCR-2418?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]

angela resolved JCR-2418.
-------------------------

       Resolution: Fixed
    Fix Version/s: 2.0-beta4
         Assignee: angela

applied patch with minor modification (referring to this issue in the comments added to ItemManager)

> Read permission on parent node required to access an item's definition
> ----------------------------------------------------------------------
>
>                 Key: JCR-2418
>                 URL: https://issues.apache.org/jira/browse/JCR-2418
>             Project: Jackrabbit Content Repository
>          Issue Type: Bug
>          Components: jackrabbit-core
>            Reporter: angela
>            Assignee: angela
>             Fix For: 2.0-beta4
>
>         Attachments: JCR-2418.patch
>
>
> If a session is granted all permissions on a given item B but lacks permission to read
it's parent node A an attempt to
> access the definition of B by means of Node.getDefinition or Property.getDefinition will
fail with AccessDeniedException.
> Similarly, the same session will not be able to modify that item B - e.g. add a child
node in case it was a node - since implementation e.g. checks of that
> item B isn't protected, which is determined by looking at the definition.
> My feeling is, that the item definition should be accessible even if the parent node
cannot be read.

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.


Mime
View raw message