Uploaded image for project: 'eZ Publish / Platform'
  1. eZ Publish / Platform
  2. EZP-29142

Content Create No draft is accessible anonymously

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Confirmed
    • Priority: Medium
    • Resolution: Unresolved
    • Affects Version/s: 2.1.0
    • Fix Version/s: None
    • Component/s: Security
    • Labels:

      Description

      Just after installing ezplatform is perfectly possible to access urls like
      http://localhost/create/nodraft/folder/eng-GB/2

      This allows you to see the form with the fields related to that content type. If you try to publish then you get a permission problem, but i'd expect to have this restriction also for this create/nodraft module.

      If this is not made in purpouse, i'd say we should protect that and only give access to users with the proper permissions

        Attachments

          Activity

            People

            Assignee:
            Unassigned
            Reporter:
            desorden Carlos Revillo
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Dates

              Created:
              Updated: