mahara-contributors team mailing list archive
-
mahara-contributors team
-
Mailing list archive
-
Message #57845
[Bug 1840201] A change has been merged
Reviewed: https://reviews.mahara.org/10838
Committed: https://git.mahara.org/mahara/mahara/commit/42332f7c547376781e539c84340347921bfcc546
Submitter: Robert Lyon (robertl@xxxxxxxxxxxxxxx)
Branch: 18.10_STABLE
commit 42332f7c547376781e539c84340347921bfcc546
Author: Robert Lyon <robertl@xxxxxxxxxxxxxxx>
Date: Wed Mar 11 09:46:28 2020 +1300
Bug 1866913: Add parts of missing function from master that are needed
Fix for bug 1840201 in 19.04
Change-Id: I20f41cb9557f3fa24a48e7e05a185ab1f72e5658
Signed-off-by: Robert Lyon <robertl@xxxxxxxxxxxxxxx>
(cherry picked from commit 41c210f3b6a66e520d7ea6b460b3615d7b839f8d)
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: Subscription for all Mahara Contributors -- please ask on #mahara-dev or mahara.org forum before editing or unsubscribing it!
https://bugs.launchpad.net/bugs/1840201
Title:
Elastic search: Search results are not restricted for aretfacts on
pages shared with group
Status in Mahara:
Fix Committed
Status in Mahara 18.10 series:
Fix Released
Status in Mahara 19.04 series:
Fix Released
Status in Mahara 19.10 series:
Fix Released
Status in Mahara 20.04 series:
Fix Committed
Bug description:
A user can create a page with media artefacts on it and share it with
a group. The user can specify which users in that group have access,
i.e "Everyone in group", "Member" and "Admin". When a user selects to
share the page with "Member" or "Admin" all members of the group can
view via the media category in Elastic Search page and can see the
artefact. The preview image for an Image block for this issue is
displaying as a broken link in FireFox and not displaying at all in
Chrome.
Have Elastic Search set up and able to search.
1. Create a group that has admin and members.
2. Log in as a user (doesn't have to be group member) and create a page with an Image block.
3. Share the page with the group and choose "Admin" in dropdown
4. Log in as an Member of the group and go to Elastic search with no search words (should return everything you have access to see.
5. Select Media tab and view
Expected results:
No artefacts from pages that are not shared with User are returned as results.
Actual results:
User can see artefacts from the page they do not have permission to access.
Mahara: 19.10dev
OS: Ubunt 18.04.2
DB: Postgres
Browser: Firefox 68.01, Chrome 75.0.3770.142
To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/1840201/+subscriptions
References