Uploaded image for project: 'ModeShape'
  1. ModeShape
  2. MODE-2428

ACLs not checked when updating properties

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • 4.2.0.Final
    • 4.1.0.Final
    • JCR
    • None

      When a property is updated (with property.setValue), the credentials are never checked. AbstractJcrProperty (or its set of sub-classes) seems to be missing any credential check.

      I'm assuming this is by design, but this seems to be a security loophole.

              hchiorean Horia Chiorean (Inactive)
              osmandin Osman Din (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: