KARL User Manual - Forbidden Error for Affiliates

Bug #422131 reported by Jason Lantz
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
KARL3
Fix Released
Medium
Chris Rossi

Bug Description

Tom reported a problem with the Help link at the bottom of the page for affilaite users. I was able to recreate the problem with user "moroztom". After logging in, click the Help link at the bottom and you get a Forbidden error page. The About KARL community is visible by the user as well as the wiki in that community. However, clicking on the KARL User Manual link produces the Forbidden error page again. It appears there are specific acl's in that community that are out of whack. That community should be visible to all users of the system.

Revision history for this message
Paul Everitt (paul-agendaless) wrote :

Yep, that's a bug. Affiliates can get to the /communties/about-karl and the /communities/about-karl/wiki/front_page/ but not to any other wiki pages that are links from there. Smells like a bug we had previously, perhaps with Oxfam, during their migration.

The shocking (in a good way) thing is, ChrisM's workflow-security-geddon fixed this!! I just tried:

  http://kdi-dev.sixfeetup.com/communities/about-karl/wiki/frequently-asked-questions/

...as an affiliate, and it worked. Of course, we have many hours of testing to find out what else we might have broken.

Chris, I'll leave this as assigned to you, just to remind us to test it after we rollout mcdonc's changes. Or, if we have to bail on those changes, we'll go ahead and fix this bug.

Changed in karl3:
assignee: nobody → Chris Rossi (chris-archimedeanco)
importance: Undecided → Medium
milestone: none → m30
Changed in karl3:
status: New → In Progress
status: In Progress → New
Revision history for this message
Chris Rossi (chris-archimedeanco) wrote :

This appears to be fixed. See staging server.

Changed in karl3:
status: New → Fix Committed
Changed in karl3:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.