[jboss-jira] [JBoss JIRA] Created: (JBPORTAL-1212) Fine Grained CMS permissions not accurately enforced in a clustered environment

Sohil Shah (JIRA) jira-events at jboss.com
Mon Jan 22 13:02:53 EST 2007


Fine Grained CMS permissions not accurately enforced in a clustered environment
-------------------------------------------------------------------------------

                 Key: JBPORTAL-1212
                 URL: http://jira.jboss.com/jira/browse/JBPORTAL-1212
             Project: JBoss Portal
          Issue Type: Bug
      Security Level: Public (Everyone can see)
          Components: Portal CMS
    Affects Versions: 2.6.Alpha1
            Reporter: Sohil Shah
         Assigned To: Sohil Shah
             Fix For: 2.6.Beta1


Problem Explanation:

Due to issues with JackRabbit internal caching, the PortalCMS Service is setup as a HA-Singleton service in a clustered environment.

One side effect is that, when PortalCMS calls are made from nodes other than the singleton node, the User Principal is not propagated through the Singleton Proxy.

Hence, the call is treated as an "Anoymous" user call instead of the currently "Logged In" User.


Note: This is not an issue in a non-clustered environment

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://jira.jboss.com/jira/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        



More information about the jboss-jira mailing list