← Back to team overview

mahara-contributors team mailing list archive

[Bug 2010052] [NEW] Access denied for Group Files in Group Journal

 

Public bug reported:

In Mahara 22.04. our users cannot create group journal entries with
embedded images, and when files are added as attachments to this entry,
they cannot be downloaded (an access denied message is shown). The
uploaded files are accessible (and downloadable) in the group files
section, so users should be able to access them (permissions are all
selected).

Steps to reproduce:
1. Create a Group
2. Add a Group Journal
3. Add a entry to that journal
4. Embedded an image in the entry textfield
5. Create an attachment to that entry
6. Submit

Expected behaviour: Show image in entry and allow download of
attachment.

Actual behaviour: No image (browser console shows an 403 error), access
denied message when trying to download attachment.

The same is true for embedding images in the journal description.
Embedding an image from the users own files seems to work.

We run Mahara 22.04.3 on MySQL 8.0.32 and PHP7.4. However, I also tested
it on the demo platform (https://demo.mahara.org/) with the same result.
As far as I can reproduce, it works as expected in Mahara 20.10 and
breaks in Mahara 21.04. I attach a screenshot of my test on the demo
platform.

** Affects: mahara
     Importance: Undecided
         Status: New

** Attachment added: "maharademo-testentry-console.png"
   https://bugs.launchpad.net/bugs/2010052/+attachment/5653554/+files/maharademo-testentry-console.png

-- 
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: mahara-contributors
https://bugs.launchpad.net/bugs/2010052

Title:
  Access denied for Group Files in Group Journal

Status in Mahara:
  New

Bug description:
  In Mahara 22.04. our users cannot create group journal entries with
  embedded images, and when files are added as attachments to this
  entry, they cannot be downloaded (an access denied message is shown).
  The uploaded files are accessible (and downloadable) in the group
  files section, so users should be able to access them (permissions are
  all selected).

  Steps to reproduce:
  1. Create a Group
  2. Add a Group Journal
  3. Add a entry to that journal
  4. Embedded an image in the entry textfield
  5. Create an attachment to that entry
  6. Submit

  Expected behaviour: Show image in entry and allow download of
  attachment.

  Actual behaviour: No image (browser console shows an 403 error),
  access denied message when trying to download attachment.

  The same is true for embedding images in the journal description.
  Embedding an image from the users own files seems to work.

  We run Mahara 22.04.3 on MySQL 8.0.32 and PHP7.4. However, I also
  tested it on the demo platform (https://demo.mahara.org/) with the
  same result. As far as I can reproduce, it works as expected in Mahara
  20.10 and breaks in Mahara 21.04. I attach a screenshot of my test on
  the demo platform.

To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/2010052/+subscriptions



Follow ups