Uploaded image for project: 'Sakai'
  1. Sakai
  2. SAK-13946

FileArtifactFinder.findByOwnerAndType() and overrides ignore owner parameter

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: CLOSED
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: 2.5.0
    • Fix Version/s: 2.6.0
    • Component/s: Metaobj
    • Labels:
      None

      Description

      The implementations of findByOwnerAndType in FileArtifactFinder and WrappedStructuredArtifactFinder do not use the owner parameter to filter at all. They are only called for portfolio assembly, and only as the current user, which is already being enforced by permissions. This means that the current bad behavior is only visible when assembling a portfolio as an admin user – all users' items of the specified type are available for selection.

        Gliffy Diagrams

          Zeplin

            Attachments

              Issue Links

                Activity

                  People

                  • Assignee:
                    noahbotimer Noah Botimer
                    Reporter:
                    noahbotimer Noah Botimer
                  • Votes:
                    0 Vote for this issue
                    Watchers:
                    0 Start watching this issue

                    Dates

                    • Created:
                      Updated:
                      Resolved:

                      Git Integration