[jboss-jira] [JBoss JIRA] Commented: (JBPORTAL-2011) HelloWorldPortal: can not access /portal/portal/HelloPortal
Thomas Heute (JIRA)
jira-events at lists.jboss.org
Fri May 9 03:19:32 EDT 2008
[ http://jira.jboss.com/jira/browse/JBPORTAL-2011?page=comments#action_12412273 ]
Thomas Heute commented on JBPORTAL-2011:
----------------------------------------
It seems that there is some inconsistency in the security rules.
Accessing: http://localhost:8080/portal/portal/HelloPortal requires authorization on the portal level (page level is not enough)
Accessing: http://localhost:8080/portal/portal/HelloPortal/foobar works. (Authorized on the page level, still not authorized on the portal level)
> HelloWorldPortal: can not access /portal/portal/HelloPortal
> -----------------------------------------------------------
>
> Key: JBPORTAL-2011
> URL: http://jira.jboss.com/jira/browse/JBPORTAL-2011
> Project: JBoss Portal
> Issue Type: Bug
> Security Level: Public(Everyone can see)
> Components: Portal Core
> Affects Versions: 2.4.3 Final
> Environment: OS: Red Hat Enterprise Linux Client release 5.1 (Tikanga)
> JBoss AS 4.2.2
> JDK 1.5 build 14
> Java Packages:
> - java-1.5.0-sun-plugin-1.5.0.15-1jpp.2.el5
> - java-1.5.0-sun-1.5.0.15-1jpp.2.el5
> - java-1.5.0-sun-devel-1.5.0.15-1jpp.2.el5
> Reporter: Murray McAllister
> Assigned To: Julien Viet
> Priority: Minor
>
> http://docs.jboss.com/jbportal/v2.6.4/referenceGuide/html/xmldescriptors.html#desc_example_portal
> To reproduce:
> 1. Download http://anonsvn.jboss.org/repos/portletswap/portlets/2_4/bundles/HelloWorldPortal.zip
> 2. Copy helloworldportal.war to the /deploy/ directory.
> 3. Navigate to http://localhost:8080/portal/portal/HelloPortal
> Results: a log in prompt. I tried logging in with the default credentials, then a "403, Access to the specified resource () has been forbidden." error occurred.
> Navigating to http://localhost:8080/portal/portal/HelloPortal/foobar works as expected.
> Thanks!
--
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://jira.jboss.com/jira/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira
More information about the jboss-jira
mailing list