respect/obey object permissions (beyond global) with plugin pivottable
To be reproduced in short.
Cases to be handled properly:
a) granted globally but restricted locally
b) granted only locally
Reproduced:
admin access:
http://xavi-9794-6148.show.tikiwiki.org
u: admin
p: 12345
Case a) granted globally but restricted locally
http://xavi-9794-6148.show.tikiwiki.org/tiki-index.php?page=Homepage+for+Staff
u: client1
p: client1
Group clients has global perms to view and edit wiki pages, but for that specific page, Clients can only see the page, and not edit it (managed through object perms).
However, user client1 currently can see the button to "Edit pivot table" (by mistake), while can't see the button to edit the wiki page (as expected). If the user clicks at edit pivot table, can change controls, but at saving time, nothing is changed (as expected, since he/she doesn't have perm on that page to edit it).
Case b) granted only locally
http://xavi-9794-6148.show.tikiwiki.org/tiki-index.php?page=Homepage+for+Staff
u: staff1
p: staff1
That page has object perms (not global) for group staff to view and edit. User staff1 can edit the page, but this user doesn't see the controls to edit the pivottable plugin.
To help developers solve the bug, we kindly request that you demonstrate your bug on a show2.tiki.org instance. To start, simply select a version and click on "Create show2.tiki.org instance". Once the instance is ready (in a minute or two), as indicated in the status window below, you can then access that instance, login (the initial admin username/password is "admin") and configure the Tiki to demonstrate your bug. Priority will be given to bugs that have been demonstrated on show2.tiki.org.
filename | created | hits | comment | version | filetype | ||
---|---|---|---|---|---|---|---|
No attachments for this item |