<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic security issue in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/security-issue/m-p/26892#M13448</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;i have created a node with &lt;/SPAN&gt;&lt;STRONG&gt;user:&lt;/STRONG&gt;&lt;SPAN&gt; admin and tryed to access it using &lt;/SPAN&gt;&lt;STRONG&gt;user:&lt;/STRONG&gt;&lt;SPAN&gt; user1, i am able to access it, even when i set to read permission to false. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;accoring to the wiki the &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;"on the NodeService bean, the readProperties method checks that the current user has read access to the properties of the node before invoking the method. On the SearchService, the results from queries are restricted to return only the nodes for which a user has read permission. "&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;my question is how can i set alfresco to automattically check the permission using "aop" i.e as quoted above.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 07 Jan 2006 15:33:14 GMT</pubDate>
    <dc:creator>pmarreddy</dc:creator>
    <dc:date>2006-01-07T15:33:14Z</dc:date>
    <item>
      <title>security issue</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/security-issue/m-p/26892#M13448</link>
      <description>hi,i have created a node with user: admin and tryed to access it using user: user1, i am able to access it, even when i set to read permission to false. accoring to the wiki the "on the NodeService bean, the readProperties method checks that the current user has read access to the properties of the</description>
      <pubDate>Sat, 07 Jan 2006 15:33:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/security-issue/m-p/26892#M13448</guid>
      <dc:creator>pmarreddy</dc:creator>
      <dc:date>2006-01-07T15:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: security issue</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/security-issue/m-p/26893#M13449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It would help to know the repository version and what you are doing.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If you are using version 1.1.1 you need to use version 1.1.2 to fix a security issue about permission enforcement.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If you are using the 1.0 open version, permissions were not included in this release.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If you are using the API direct, only the public service beans apply permission. There are two versions of these public beans. For example, "nodeService" and "NodeService". "nodeService" does not apply security, it is wrapped by "NodeService" which applies security. The same pattern applies to "searchService" and "SearchService".&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2006 10:11:44 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/security-issue/m-p/26893#M13449</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2006-01-09T10:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: security issue</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/security-issue/m-p/26894#M13450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;thank u for ur promt reply.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;prasanth&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2006 16:49:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/security-issue/m-p/26894#M13450</guid>
      <dc:creator>pmarreddy</dc:creator>
      <dc:date>2006-01-09T16:49:14Z</dc:date>
    </item>
  </channel>
</rss>

