| Summary: | [user] Fix holes in the Orion authorization | ||
|---|---|---|---|
| Product: | [ECD] Orion | Reporter: | Szymon Brandys <Szymon.Brandys> |
| Component: | Server | Assignee: | Project Inbox <orion.server-inbox> |
| Status: | RESOLVED WONTFIX | QA Contact: | |
| Severity: | major | ||
| Priority: | P3 | CC: | john.arthorne |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | All | ||
| Whiteboard: | |||
| Bug Depends on: | 337582 | ||
| Bug Blocks: | |||
|
Description
Szymon Brandys
Will continue in M7. Note we currently have hard-coded settings in AuthorizationService, such as always granting users access to /workspace, /site, their own user profile, etc. I expect the right longer term solution is that these "default" rights come from the user's role, and the rights associated with the role are configurable somehow. Closing as part of a mass clean up of inactive bugs. Please reopen if this problem still occurs or is relevant to you. For more details see: https://dev.eclipse.org/mhonarc/lists/orion-dev/msg03444.html |