<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Restricted access to getTargetAssocsByPropertyValue in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/restricted-access-to-gettargetassocsbypropertyvalue/m-p/89954#M26891</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Using the capitalised NodeService bean, nodeService.getTargetAssocsByPropertyValue can only be run by the &lt;EM&gt;system&lt;/EM&gt; user. This is due to the bean &lt;EM&gt;id="NodeService_security"&lt;/EM&gt; in &lt;EM&gt;alfresco-repository/src/main/resources/alfresco/public-services-security-context.xml &lt;/EM&gt;, in which there is no entry for this method so it defaults to ACL_DENY, preventing access.&lt;BR /&gt;&lt;BR /&gt;Considering that similar methods (e.g. getChildAssocsByPropertyValue) have entries, it seems as though this might be a mistake/bug, unless there is some specific reason that this method should not be used?&lt;BR /&gt;&lt;BR /&gt;Does anyone know anything about this?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Sam Cheshire&lt;/P&gt;</description>
    <pubDate>Wed, 25 Sep 2019 12:08:51 GMT</pubDate>
    <dc:creator>scrasun</dc:creator>
    <dc:date>2019-09-25T12:08:51Z</dc:date>
    <item>
      <title>Restricted access to getTargetAssocsByPropertyValue</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/restricted-access-to-gettargetassocsbypropertyvalue/m-p/89954#M26891</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Using the capitalised NodeService bean, nodeService.getTargetAssocsByPropertyValue can only be run by the &lt;EM&gt;system&lt;/EM&gt; user. This is due to the bean &lt;EM&gt;id="NodeService_security"&lt;/EM&gt; in &lt;EM&gt;alfresco-repository/src/main/resources/alfresco/public-services-security-context.xml &lt;/EM&gt;, in which there is no entry for this method so it defaults to ACL_DENY, preventing access.&lt;BR /&gt;&lt;BR /&gt;Considering that similar methods (e.g. getChildAssocsByPropertyValue) have entries, it seems as though this might be a mistake/bug, unless there is some specific reason that this method should not be used?&lt;BR /&gt;&lt;BR /&gt;Does anyone know anything about this?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Sam Cheshire&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 12:08:51 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/restricted-access-to-gettargetassocsbypropertyvalue/m-p/89954#M26891</guid>
      <dc:creator>scrasun</dc:creator>
      <dc:date>2019-09-25T12:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: Restricted access to getTargetAssocsByPropertyValue</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/restricted-access-to-gettargetassocsbypropertyvalue/m-p/89955#M26892</link>
      <description>&lt;P&gt;This is most definitely a bug / massive oversight in development + testing by Alfresco. It is unfortunately not that uncommon, as I have had to report various methods with missing security configurations myself in the past.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 14:13:02 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/restricted-access-to-gettargetassocsbypropertyvalue/m-p/89955#M26892</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2019-09-25T14:13:02Z</dc:date>
    </item>
  </channel>
</rss>

