I am using Alfresco 2.1 community edition with WCM.
I am using the web site submission workflow - serial option - ……. to create content. In the workflow I am selecting a user who is Content publisher to review and publish it. This user can see the task and approve it.
But it looks like there is a security hole. Any user who has minimal permission of Content Creator logs in and enables "All Active Task" in My Alfresco not only sees this task but also can approve the task.
How can one prevent this form happening in the default web site submission workflow.
What about to extend permissions to web forms themselves?
I mean, we have some security breaches in web forms in the way that a content contributor, i.e., from HR department could submit a product release web form since she can see all web project forms from her sandbox!
I know that an workflow could prevent that form to be published by some reviewer, however, you would agree that is not the desirable way to deal with it.