Uploaded image for project: 'eZ Publish / Platform'
  1. eZ Publish / Platform
  2. EZP-29316

UI admin allows user to create custom urls regardless of policy

    XMLWordPrintable

Details

    Description

      The combination of admin ui not disabling the create button and that UrlAliasController performs no checks if the user is allowed to create urls, a user is allow_content_types to do so even if they do not have the rights to url.

      Perhaps url policies should be separate from polices for urlalias.

      Attachments

        Activity

          People

            Unassigned Unassigned
            feb52ca2-9206-4fa9-818f-2c4dcf3f42b0@accounts.ibexa.co Douglas Hammond
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: