[Cubicweb] Search behavior on CubicWeb - users access

Sylvain Thénault sylvain.thenault at logilab.fr
Mon Aug 26 15:03:46 CEST 2013


On 23 août 01:25, Celso FLORES wrote:
> Hi List,

Hi Celso,
 
> Some of our users/developers have found this search behavior at CubicWeb:
> 
> - There are some entities which can not be read by certain group.
> - Those entities are shown at the search results, and then we can't open
> the link, as the user doesn't have the right to see it.
> 
> Two questions appeared :
> 1. Do Search behavior validates any reading access from the current user?
> if not,
> 2. Is there any form to do this ? (or any place where we may start
> looking).

This definitly sounds like a bug. The easiest way to move on this would probably
be to provide a minimal (test) case describing the pb, probably in a dedicated 
cube. Else more context including the read permissions of the problematic entity
type and the example rql query would be a good start.

-- 
Sylvain Thénault, LOGILAB, Paris (01.45.32.03.12) - Toulouse (05.62.17.16.42)
Formations Python, Debian, Méth. Agiles: http://www.logilab.fr/formations
Développement logiciel sur mesure:       http://www.logilab.fr/services
CubicWeb, the semantic web framework:    http://www.cubicweb.org



More information about the Cubicweb mailing list