[
http://jira.jboss.com/jira/browse/JBPORTAL-328?page=comments#action_12342566 ]
orionyiu commented on JBPORTAL-328:
-----------------------------------
When creating/editng CMS folder, files, there should be a feature for setting the security
level for that object (like that in setting security for portlet instance/page).
Subsequently when user browse through the CMS directory tree they should only be able to
see the folder/files they are entitiled to see.
Preferably when setting security, there should be options for setting whether a role has
permission to "view" and/or "edit".
CMS security
------------
Key: JBPORTAL-328
URL:
http://jira.jboss.com/jira/browse/JBPORTAL-328
Project: JBoss Portal
Issue Type: Task
Security Level: Public(Everyone can see)
Components: Portal CMS
Affects Versions: 2.6 Final
Reporter: Julien Viet
Assigned To: Roy Russo
Fix For: 2.6 Final
Improve the current CMS security.
No check is done at the CMSPortlet level, this is a important missing feature.
--
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators:
http://jira.jboss.com/jira/secure/Administrators.jspa
-
For more information on JIRA, see:
http://www.atlassian.com/software/jira