Uploaded image for project: 'ModeShape'
  1. ModeShape
  2. MODE-2428

ACLs not checked when updating properties

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Major
    • 4.2.0.Final
    • 4.1.0.Final
    • JCR
    • None

    Description

      When a property is updated (with property.setValue), the credentials are never checked. AbstractJcrProperty (or its set of sub-classes) seems to be missing any credential check.

      I'm assuming this is by design, but this seems to be a security loophole.

      Attachments

        Activity

          People

            hchiorean Horia Chiorean (Inactive)
            osmandin Osman Din (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: