Fine Grained CMS permissions not accurately enforced in a clustered environment
-------------------------------------------------------------------------------
Key: JBPORTAL-1212
URL:
http://jira.jboss.com/jira/browse/JBPORTAL-1212
Project: JBoss Portal
Issue Type: Bug
Security Level: Public (Everyone can see)
Components: Portal CMS
Affects Versions: 2.6.Alpha1
Reporter: Sohil Shah
Assigned To: Sohil Shah
Fix For: 2.6.Beta1
Problem Explanation:
Due to issues with JackRabbit internal caching, the PortalCMS Service is setup as a
HA-Singleton service in a clustered environment.
One side effect is that, when PortalCMS calls are made from nodes other than the singleton
node, the User Principal is not propagated through the Singleton Proxy.
Hence, the call is treated as an "Anoymous" user call instead of the currently
"Logged In" User.
Note: This is not an issue in a non-clustered environment
--
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators:
http://jira.jboss.com/jira/secure/Administrators.jspa
-
For more information on JIRA, see:
http://www.atlassian.com/software/jira