Bug #32209
closed
Be user with explicit deny can edit the content plugin fields
Added by David Denicolo' almost 13 years ago.
Updated about 6 years ago.
Description
If a Admin create plugin news the editor with explict deny on content plugin news can edit this plugin, he see [invalid value "9"] in the select plugin selector but every other input box or selector is editable so the editor can change the plugin option.
Simple he cannot create another one but can change everything in the plugin.
TYPO3 version 4.5.8
Thanks
Files
This bug still exists in TYPO3 6.x.
In one of our installations (6.1) we have a very specified management of user rights with more than 20 editors and a lot of roles. Some may edit and create certain content, some may not. The editors, who may not create plugins like news or powermail can open such a content element and change the settings, e.g. the list_type of a plugin.
This bug should be fixed to have a valid userright's mangament by using the explicit deny functionality.
Thx.
- Target version set to 7.4 (Backend)
- Is Regression set to No
- Target version changed from 7.4 (Backend) to 7.5
- Target version changed from 7.5 to 7 LTS
- Target version changed from 7 LTS to next-patchlevel
- Target version deleted (
next-patchlevel)
- Project changed from TYPO3 Core to 1716
- Status changed from New to Under Review
Patch set 1 for branch master of project Teams/Security/TYPO3v4-Core has been pushed to the review server.
It is available at https://review.typo3.org/45163
- Project changed from 1716 to TYPO3 Core
- Is Regression set to No
- Status changed from Under Review to Resolved
- % Done changed from 0 to 100
- Status changed from Resolved to Closed
Also available in: Atom
PDF