Uploaded image for project: 'Apache Roller'
  1. Apache Roller
  2. ROL-826

Author of multi-user blog has access to the settings of blog although he's not an administrator

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Minor
    • Resolution: Fixed
    • 2.0
    • 2.0
    • None
    • blogs.sfbay.sun.com testing environment
    • firefox
    • blogs.sun.com

    Description

      Testing the multi-author feature, I had the following accesses:
      my blog: Admin
      blog2: author.

      In the main menu panel, for each blog there is a list of actions that I can do: New entries, Edit Entries, Settings.
      The Settings action is present for blog2 although I'm just an author and shouldn't be able to change any settings in the blog2.
      Clicking on Settings display a Permission Denied page with possible reasons.

      This is a usability issue. The settings link should have been disabled.

      Attachments

        Activity

          People

            djohnson David Johnson
            ludo ludovic poitou
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: