Details
-
Bug
-
Resolution: Fixed
-
Medium
-
3.3.19
-
None
-
None
-
Ibexa Commerce, Ibexa Content, Ibexa Experience, Ibexa Open Source
Description
(Ibexa Experience v3.3.19 or later)
Steps to reproduce:
Scenario:
- assume havingĀ 2 Content Objects: main-content & related-content
- assume 2 Users: admin & non-admin
- related-content is related to main-content through an ezobjectrelation Field.
- non-admin can read/edit/publish main-content and has no permissions on related-content.
- admin publishes a new version of main-content with a relation to related-content
- non-admin edits main-content and tries to publish
Result:
Publishing fails showing the error Content with identifier XX is not a valid relation target
(Error is thrown by Ibexa\Core\Repository\Validator\TargetContentValidator )
Expected:
Publishing should succeed as non-admin is not seeing or changing related-content.
(This was the actual behaviour until v3.3.18)
Note:
Change was introduced to fix https://issues.ibexa.co/browse/IBX-1669 (see https://github.com/ezsystems/ezpublish-kernel/pull/3131)
Designs
Attachments
Issue Links
- relates to
-
IBX-1669 'ezobjectrelation' field is not validated when using Public API
- Closed