<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Bug or security policy? in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/bug-or-security-policy/m-p/239234#M192364</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi, All&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have a problem, but don't understand it.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;User1 and User2 have Contributor role.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;At Discussion section&amp;nbsp; - if User1 is creating message, User2 is able to add comment to it.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;But at Blog section - If User2 is creating message, User2 unable to add comment - Access Denied.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;At alfresco.log I see:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;11:41:44,459 ERROR [org.alfresco.web.scripts.AbstractRuntime] Exception from executeScript - redirecting to status template error: 06230076 Wrapped Exception (with status template): 06230075 Failed to execute script '/org/alfresco/repository/comments/comments.post.json.js (in classpath store file:/opt/Alfresco/tomcat/webapps/alfresco/WEB-INF/classes/alfresco/templates/webscripts)': 06230074&amp;nbsp; Access Denied.You do not have the appropriate permissions to perform this operation.&lt;BR /&gt;org.alfresco.web.scripts.WebScriptException: 06230076 Wrapped Exception (with status template): 06230075 Failed to execute script '/org/alfresco/repository/comments/comments.post.json.js (in classpath store file:/opt/Alfresco/tomcat/webapps/alfresco/WEB-INF/classes/alfresco/templates/webscripts)': 06230074 Access Denied.You do not have the appropriate permissions to perform this operation.&lt;BR /&gt;at org.alfresco.web.scripts.AbstractWebScript.createStatusException(AbstractWebScript.java:613)&lt;BR /&gt;at org.alfresco.web.scripts.DeclarativeWebScript.execute(DeclarativeWebScript.java:165)&lt;BR /&gt;at org.alfresco.repo.web.scripts.RepositoryContainer$2.execute(RepositoryContainer.java:357)&lt;BR /&gt;at org.alfresco.repo.transaction.RetryingTransactionHelper.doInTransaction(RetryingTransactionHelper.java:326)&lt;BR /&gt;at org.alfresco.repo.web.scripts.RepositoryContainer.transactionedExecute(RepositoryContainer.java:407)&lt;BR /&gt;at org.alfresco.repo.web.scripts.RepositoryContainer.transactionedExecuteAs(RepositoryContainer.java:424)&lt;BR /&gt;at org.alfresco.repo.web.scripts.RepositoryContainer.executeScript(RepositoryContainer.java:288)&lt;BR /&gt;at org.alfresco.web.scripts.AbstractRuntime.executeScript(AbstractRuntime.java:262)&lt;BR /&gt;at org.alfresco.web.scripts.AbstractRuntime.executeScript(AbstractRuntime.java:139)&lt;BR /&gt;at org.alfresco.web.scripts.servlet.WebScriptServlet.service(WebScriptServlet.java:122)&lt;BR /&gt;at javax.servlet.http.HttpServlet.service(HttpServlet.java:717)&lt;BR /&gt;at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290)&lt;BR /&gt;at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)&lt;BR /&gt;at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:233)&lt;BR /&gt;at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:191)&lt;BR /&gt;at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:128)&lt;BR /&gt;at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102)&lt;BR /&gt;at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)&lt;BR /&gt;at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:286)&lt;BR /&gt;at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:845)&lt;BR /&gt;at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:583)&lt;BR /&gt;at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:447)&lt;BR /&gt;at java.lang.Thread.run(Thread.java:619)&lt;BR /&gt;Caused by: org.alfresco.scripts.ScriptException: 06230075 Failed to execute script '/org/alfresco/repository/comments/comments.post.json.js (in classpath store file:/opt/Alfresco/tomcat/webapps/alfresco/WEB-INF/classes/alfresco/templates/webscripts)': 06230074&amp;nbsp; Access Denied.You do not have the appropriate permissions to perform this operation.&lt;BR /&gt;at org.alfresco.repo.jscript.RhinoScriptProcessor.execute(RhinoScriptProcessor.java:178)&lt;BR /&gt;at org.alfresco.repo.processor.ScriptServiceImpl.executeScript(ScriptServiceImpl.java:274)&lt;BR /&gt;at org.alfresco.repo.web.scripts.RepositoryScriptProcessor.executeScript(RepositoryScriptProcessor.java:108)&lt;BR /&gt;at org.alfresco.web.scripts.AbstractWebScript.executeScript(AbstractWebScript.java:819)&lt;BR /&gt;at org.alfresco.web.scripts.DeclarativeWebScript.execute(DeclarativeWebScript.java:90)&lt;BR /&gt;… 21 more&lt;BR /&gt;Caused by: org.alfresco.repo.security.permissions.AccessDeniedException: 06230074 Access Denied.You do not have the appropriate permissions to perform this operation.&lt;BR /&gt;at org.alfresco.repo.security.permissions.impl.ExceptionTranslatorMethodInterceptor.invoke(ExceptionTranslatorMethodInterceptor.java:53)&lt;BR /&gt;at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:171)&lt;BR /&gt;at org.alfresco.repo.audit.AuditComponentImpl.audit(AuditComponentImpl.java:275)&lt;BR /&gt;at org.alfresco.repo.audit.AuditMethodInterceptor.invoke(AuditMethodInterceptor.java:69)&lt;BR /&gt;at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:171)&lt;BR /&gt;at org.springframework.transaction.interceptor.TransactionInterceptor.invoke(TransactionInterceptor.java:106)&lt;BR /&gt;at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:171)&lt;BR /&gt;at org.springframework.aop.framework.JdkDynamicAopProxy.invoke(JdkDynamicAopProxy.java:204)&lt;BR /&gt;at $Proxy9.addAspect(Unknown Source)&lt;BR /&gt;at org.alfresco.repo.jscript.ScriptNode.addAspect(ScriptNode.java:1501)&lt;BR /&gt;at org.alfresco.repo.jscript.ScriptNode.addAspect(ScriptNode.java:1478)&lt;BR /&gt;at sun.reflect.GeneratedMethodAccessor2248.invoke(Unknown Source)&lt;BR /&gt;at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)&lt;BR /&gt;at java.lang.reflect.Method.invoke(Method.java:597)&lt;BR /&gt;at org.mozilla.javascript.MemberBox.invoke(MemberBox.java:155)&lt;BR /&gt;at org.mozilla.javascript.NativeJavaMethod.call(NativeJavaMethod.java:243)&lt;BR /&gt;at org.mozilla.javascript.optimizer.OptRuntime.call1(OptRuntime.java:66)&lt;BR /&gt;at org.mozilla.javascript.gen.c51._c8(file:/opt/Alfresco/tomcat/webapps/alfresco/WEB-INF/classes/alfresco/templates/webscripts/org/alfresco/repository/comments/comments.post.json.js:179)&lt;BR /&gt;at org.mozilla.javascript.gen.c51.call(file:/opt/Alfresco/tomcat/webapps/alfresco/WEB-INF/classes/alfresco/templates/webscripts/org/alfresco/repository/comments/comments.post.json.js)&lt;BR /&gt;at org.mozilla.javascript.optimizer.OptRuntime.callName(OptRuntime.java:97)&lt;BR /&gt;at org.mozilla.javascript.gen.c51._c11(file:/opt/Alfresco/tomcat/webapps/alfresco/WEB-INF/classes/alfresco/templates/webscripts/org/alfresco/repository/comments/comments.post.json.js:222)&lt;BR /&gt;at org.mozilla.javascript.gen.c51.call(file:/opt/Alfresco/tomcat/webapps/alfresco/WEB-INF/classes/alfresco/templates/webscripts/org/alfresco/repository/comments/comments.post.json.js)&lt;BR /&gt;at org.mozilla.javascript.optimizer.OptRuntime.callName(OptRuntime.java:97)&lt;BR /&gt;at org.mozilla.javascript.gen.c51._c12(file:/opt/Alfresco/tomcat/webapps/alfresco/WEB-INF/classes/alfresco/templates/webscripts/org/alfresco/repository/comments/comments.post.json.js:246)&lt;BR /&gt;at org.mozilla.javascript.gen.c51.call(file:/opt/Alfresco/tomcat/webapps/alfresco/WEB-INF/classes/alfresco/templates/webscripts/org/alfresco/repository/comments/comments.post.json.js)&lt;BR /&gt;at org.mozilla.javascript.optimizer.OptRuntime.callName0(OptRuntime.java:108)&lt;BR /&gt;at org.mozilla.javascript.gen.c51._c0(file:/opt/Alfresco/tomcat/webapps/alfresco/WEB-INF/classes/alfresco/templates/webscripts/org/alfresco/repository/comments/comments.post.json.js:266)&lt;BR /&gt;at org.mozilla.javascript.gen.c51.call(file:/opt/Alfresco/tomcat/webapps/alfresco/WEB-INF/classes/alfresco/templates/webscripts/org/alfresco/repository/comments/comments.post.json.js)&lt;BR /&gt;at org.mozilla.javascript.ContextFactory.doTopCall(ContextFactory.java:393)&lt;BR /&gt;at org.mozilla.javascript.ScriptRuntime.doTopCall(ScriptRuntime.java:2834)&lt;BR /&gt;at org.mozilla.javascript.gen.c51.call(file:/opt/Alfresco/tomcat/webapps/alfresco/WEB-INF/classes/alfresco/templates/webscripts/org/alfresco/repository/comments/comments.post.json.js)&lt;BR /&gt;at org.mozilla.javascript.gen.c51.exec(file:/opt/Alfresco/tomcat/webapps/alfresco/WEB-INF/classes/alfresco/templates/webscripts/org/alfresco/repository/comments/comments.post.json.js)&lt;BR /&gt;at org.alfresco.repo.jscript.RhinoScriptProcessor.executeScriptImpl(RhinoScriptProcessor.java:449)&lt;BR /&gt;at org.alfresco.repo.jscript.RhinoScriptProcessor.execute(RhinoScriptProcessor.java:174)&lt;BR /&gt;… 25 more&lt;BR /&gt;Caused by: net.sf.acegisecurity.AccessDeniedException: Access is denied.&lt;BR /&gt;at net.sf.acegisecurity.vote.AffirmativeBased.decide(AffirmativeBased.java:86)&lt;BR /&gt;at net.sf.acegisecurity.intercept.AbstractSecurityInterceptor.beforeInvocation(AbstractSecurityInterceptor.java:394)&lt;BR /&gt;at net.sf.acegisecurity.intercept.method.aopalliance.MethodSecurityInterceptor.invoke(MethodSecurityInterceptor.java:77)&lt;BR /&gt;at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:171)&lt;BR /&gt;at org.alfresco.repo.security.permissions.impl.ExceptionTranslatorMethodInterceptor.invoke(ExceptionTranslatorMethodInterceptor.java:49)&lt;BR /&gt;… 58 more&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Please explain me sense of Roles:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Consumer - can read only. Ok&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Contributor - can create nodes, and manage it. Hе can't change,delete nodes created by other users. But I can't understand why he can't add comments to Blog created by other users.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Collaborator&amp;nbsp; - can change anything, but can't delete nodes, created by other users.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Manager - can everything&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Sorry for my poor english.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for any answer.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Jul 2009 09:24:59 GMT</pubDate>
    <dc:creator>aleks_sh</dc:creator>
    <dc:date>2009-07-23T09:24:59Z</dc:date>
    <item>
      <title>Bug or security policy?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/bug-or-security-policy/m-p/239234#M192364</link>
      <description>Hi, AllI have a problem, but don't understand it.User1 and User2 have Contributor role.At Discussion section&amp;nbsp; - if User1 is creating message, User2 is able to add comment to it.But at Blog section - If User2 is creating message, User2 unable to add comment - Access Denied.At alfresco.log I see:11:41</description>
      <pubDate>Thu, 23 Jul 2009 09:24:59 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/bug-or-security-policy/m-p/239234#M192364</guid>
      <dc:creator>aleks_sh</dc:creator>
      <dc:date>2009-07-23T09:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Bug or security policy?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/bug-or-security-policy/m-p/239235#M192365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi, All&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Strange situation&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;User with permissions of Contributor can't add comments to blogpost until somebody with permissions of Manager(Collaborator) add his comment to that blogpost.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Any ideas?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Aleksandr&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jul 2009 14:27:20 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/bug-or-security-policy/m-p/239235#M192365</guid>
      <dc:creator>aleks_sh</dc:creator>
      <dc:date>2009-07-24T14:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: Bug or security policy?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/bug-or-security-policy/m-p/239236#M192366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Please see: &lt;/SPAN&gt;&lt;A href="https://issues.alfresco.com/jira/browse/ETHREEOH-2026" rel="nofollow noopener noreferrer"&gt;https://issues.alfresco.com/jira/browse/ETHREEOH-2026&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Mike&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jul 2009 14:37:11 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/bug-or-security-policy/m-p/239236#M192366</guid>
      <dc:creator>mikeh</dc:creator>
      <dc:date>2009-07-24T14:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: Bug or security policy?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/bug-or-security-policy/m-p/239237#M192367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;problem still unresolved in 4.0b&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;or it came back…&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Nov 2011 12:21:21 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/bug-or-security-policy/m-p/239237#M192367</guid>
      <dc:creator>aleks_sh</dc:creator>
      <dc:date>2011-11-24T12:21:21Z</dc:date>
    </item>
  </channel>
</rss>

