Bug #84554

User that has NO permission in group to delete files or folders in FAL can delete files and folders anyway

Added by Angelo Previtali over 3 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Must have
Assignee:
-
Category:
File Abstraction Layer (FAL)
Target version:
-
Start date:
2018-03-29
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
8
PHP Version:
7.1
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

By setting up a storage and a brandnew user and removing the group the permission to just READ files and NOT to delete those the user can delete files or folders anyway. That shouldn't be!

I tried it to set it in the BE user group

and by deny him the permissions in the files and folder permissions by disable this on

plus adding the PageTS Script to disallow him to deny the user on the shared storage (i.e. the storage 1)

permissions.file.storage.1 {
   addFile      = 1
   readFile     = 1
   writeFile    = 0
   copyFile     = 0
   moveFile     = 0
   renameFile   = 0
   unzipFile    = 0
   deleteFile   = 0
   addFolder    = 0
   readFolder   = 0
   writeFolder  = 0
   copyFolder   = 0
   moveFolder   = 0
   renameFolder = 0
   deleteFolder = 1
   recursivedeleteFolder = 0
}

But afterthat the user is still able to DELETE files and folders everywhere!

The set upped permission seems not to work at all! No matter what you set as permissions - nothing works!


Files

be-ansicht-gruppe-redaktoren.png (9.43 KB) be-ansicht-gruppe-redaktoren.png Angelo Previtali, 2018-03-29 11:17
redaktoreneinstellungen.png (8.94 KB) redaktoreneinstellungen.png Angelo Previtali, 2018-03-29 11:18
fileadmin-icons.png (10 KB) fileadmin-icons.png Angelo Previtali, 2018-03-29 11:21
permissions-folder-files.jpg (201 KB) permissions-folder-files.jpg File/Folder properties in fileadmin Angelo Previtali, 2018-05-16 09:22
permissions-folder-files.jpg (198 KB) permissions-folder-files.jpg Angelo Previtali, 2018-05-16 09:25
Annotation 2019-03-06 143053.png (72.7 KB) Annotation 2019-03-06 143053.png Susanne Moog, 2019-03-06 14:31

Related issues

Related to TYPO3 Core - Bug #85425: Check the copy permissions correctlyClosedGuido Schmechel2018-06-28

Actions

Also available in: Atom PDF