Uploaded image for project: 'Jackrabbit Oak'
  1. Jackrabbit Oak
  2. OAK-5354

Security: the order of child should be correct if the child nodes are readable.

    XMLWordPrintableJSON

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 1.5.17, 1.6.0
    • Component/s: None
    • Labels:
      None

      Description

      If access rights are set such that a session can read child nodes of a node, then that session should also be able to read the child nodes in the right order (for orderable nodes). Even if the session does not have permission to read the properties of a node.

      The order of child nodes is stored in a hidden property. Access rights for this hidden property are currently checked in the same way as access rights for regular properties.

        Attachments

          Activity

            People

            • Assignee:
              tmueller Thomas Mueller
              Reporter:
              tmueller Thomas Mueller
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: