Uploaded image for project: 'eZ Publish / Platform'
  1. eZ Publish / Platform
  2. EZP-18743

Able to move an article, even if it isn't defined in the roles

    Details

      Description

      Even if the move rule isn't added, the object can still be moved.

      Steps to reproduce

       
      Create Users and Groups
       
      1. Login into admin as admin
      2. Open the user accounts tab
      3. Create the following User Groups
       Group 1
       
      4. Click Group 1 link
      5. Create an User with the following data
      FirstName: user1
      Laste Name: QA
      username: user1
      password: user1
      email: test@ez.no
       
      6. Click Send for publish button
       
      Create Roles an Policies
       
      1. Open User Accounts Tab
      2. Click on Roles an Policies link
      3. Create a Role name “Role 1”
      4. Create the following policies with no limitations to (Grant full access)
       Content: Create
       Content: Edit
       Content: Read
       Content: Remove
       Content: Dashboard
       Content: VersionRead
       user: all functions
       websitetoolbar: all functions
       
      5. Verify that all of the selections are visible in the sub-items list
      6. Click Save Button
      7. Click the assign button and add “Group 1” user group
      8. Logout
       
      Verify permissions for Role 1
       
      1. Login to ezwebin site as user1
      2. Create “News” folder
      3. Create “Target” folder
      4. Click on the “News” link
      5. Create 3 Articles with the following data
      Title: Article {1,2,3}
      Summary: Intro for Article {1,2,3}
       
      6. Edit Article 1 with the following data
      Title: Article 1 v2
      Summary: Intro for Article v2
       
      7. Press Store Draft and Exit
      8. Enter Article 3
      9. Remove the Article using the toolbar
      10. Verify that the Article is no longer shown
      11. Enter Article 2
      12. Try to Move Article 2 to “Target” folder
      13. Verify that you cant move Article 2 to the target Folder
      
      

        Issue Links

          Activity

          Hide
          Pedro Resende added a comment -

          Please see test case 488

          Show
          Pedro Resende added a comment - Please see test case 488
          Hide
          Vidar Langseid added a comment -

          Hi

          Please test this in 3.9 and 4.1 and see if there is same behaviour there.
          If so, this is a documentation issue ( and test case needs update )

          Show
          Vidar Langseid added a comment - Hi Please test this in 3.9 and 4.1 and see if there is same behaviour there. If so, this is a documentation issue ( and test case needs update )
          Hide
          Jérôme Vieilledent added a comment - - edited

          Hi

          content/move action is handled through a combination of *content/edit, **content/remove* and *content/create* policies since 3.5.3 / 3.6.0 (see http://issues.ez.no/6036).
          I guess content/move policy is obsolete since this commit : https://github.com/ezsystems/ezpublish/commit/d6cbe7a58012de96ccd14396eaf64ab0149d9f70

          So if you grant full access on create/edit/remove, you will be able to move content without restriction and this is the expected result

          Show
          Jérôme Vieilledent added a comment - - edited Hi content/move action is handled through a combination of * content/edit , **content/remove * and * content/create * policies since 3.5.3 / 3.6.0 (see http://issues.ez.no/6036 ). I guess content/move policy is obsolete since this commit : https://github.com/ezsystems/ezpublish/commit/d6cbe7a58012de96ccd14396eaf64ab0149d9f70 So if you grant full access on create/edit/remove, you will be able to move content without restriction and this is the expected result

            People

            • Assignee:
              unknown
              Reporter:
              Pedro Resende
            • Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: