jackrabbit-oak-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "angela (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (OAK-2473) ACL checks on suggestions
Date Mon, 09 Feb 2015 16:08:34 GMT

    [ https://issues.apache.org/jira/browse/OAK-2473?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14312384#comment-14312384
] 

angela commented on OAK-2473:
-----------------------------

[~teofili], in fact i got you wrong... obviously you can use the unsecured {{NodeState}} with
the {{PermissionProvider}} if you also have the parents at hand (they are required for proper
permission evaluation). that's what we have the provider for in the first place... i got it
wrong as i thought you were talking about whether access to child nodes and property from
the {{NodeState}} was proper secured. that way round you would need to have the {{SecureNodeState}}.

> ACL checks on suggestions
> -------------------------
>
>                 Key: OAK-2473
>                 URL: https://issues.apache.org/jira/browse/OAK-2473
>             Project: Jackrabbit Oak
>          Issue Type: Sub-task
>          Components: oak-lucene, oak-solr, query
>            Reporter: Tommaso Teofili
>            Assignee: Tommaso Teofili
>             Fix For: 1.1.7
>
>         Attachments: OAK-2473.0.patch
>
>
> Support for ACL check suggestions needs to be added to avoid providing suggestions coming
from index data whose source nodes / properties were not meant to be readable from the calling
user.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Mime
View raw message