Uploaded image for project: 'eZ Publish / Platform'
  1. eZ Publish / Platform
  2. EZP-25447

Handle content editing framework security

    XMLWordPrintable

Details

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: High High
    • None
    • None
    • None
    • None

    Description

      At the moment, the content/create route will always display the form, even to an anonymous user. If the user does not have permissions to create, the login form will be shown on submit.

      Unless there are special use-cases, the controller should only display the form if the user has permission to create.

      Note that according to feedback in EZP-25435, this would be a problem with HTTP cache with some policies (like ParentContent conditions).

      Attachments

        Activity

          People

            Unassigned Unassigned
            andre.romcke-obsolete@ez.no André Rømcke (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: