cancel
Showing results for 
Search instead for 
Did you mean: 

Web site workflow - bug?

harshad
Champ in-the-making
Champ in-the-making
I am using Alfresco 2.1 community edition with WCM.

I am using the web site submission workflow - serial option - ……. to create content.  In the workflow I am selecting a user who is Content publisher to review and publish it. This user can see the task and approve it.

But it looks like there is a security hole. Any user who has minimal permission of Content Creator logs in and enables "All Active Task" in My Alfresco not only sees this task but also can approve the task.

How can one prevent this form happening in the default web site submission workflow.

-thanks,
4 REPLIES 4

davidc
Star Contributor
Star Contributor
Remove that dashlet via configuration, so it's not available for selection.

sacco
Champ in-the-making
Champ in-the-making
I don't really see how this closes the potential security hole, which is server-side, surely?

If it's a hole, then it remains so even if we don't provide a convenient one-click exploit (although it's obviously better no to do this).

davidc
Star Contributor
Star Contributor
Correct - the workflow service has yet to declare its permission requirements.

paulossilva
Champ in-the-making
Champ in-the-making
What about to extend permissions to web forms themselves?

I mean, we have some security breaches in web forms in the way that a content contributor, i.e.,  from HR department could submit a product release web form since she can see all web project forms from her sandbox!

I know that an workflow could prevent that form to be published by some reviewer, however, you would agree that is not the desirable way to deal with it.