[CPS-devel] Local roles, security problem?

Alberto Porras Galvez alberto.porras at iavantefundacion.com
Fri Jan 13 10:58:23 CET 2006


Hi all!
 
  I'm using CPS-3.3.8, and I have found the following error related to portal members and local roles: If I give to a member a local role in a workspace or a section and then I delete this member in the portal, the deleted member is not removed from the local roles in that workspace or section, so we have a 'phantom' member with a local role in that workspace or section but he doesn't really exist in the portal. 
  Moreover, it can lead us to a security problem if another user registers in the portal with the same username that had the old member, this new member will acquire these local roles defined for the old member.
  Is this a known bug? By the way, Is there implemented any method that lets us to delete all the defined local roles in sections and workspaces for a member?
 
Thanks!!
Alberto Porras Galvez 
Becario eSalud 
FUNDACIÓN IAVANTE 
alberto.porras at iavantefundacion.com 
Tel. 951 015 300 
 
Este correo electrónico y, en su caso, cualquier fichero anexo, contiene información confidencial exclusivamente dirigida a su(s) destinatario(s). Toda copia o divulgación deberá ser autorizada por IAVANTE.
This e-mail and any attachments are confidential and exclusively directed to its adressee(s). Any copy or distribution will have to be authorized by IAVANTE.
 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.nuxeo.com/pipermail/cps-devel/attachments/20060113/99482eba/attachment.htm


More information about the cps-devel mailing list
More information about CPS: CPS project - CVS - API

Hosting: Nuxeo: Zope service provider


This list archive provided by Nuxeo, the leaders of open source ECM. Check out the Nuxeo 5 open source, standards-based ECM project.