Hello,
When an ACL is added to Notes module, the attachments in the Notes are not affected by this ACL and anyone can view/download the attachments.
Can anyone solve it?
Regards
Hello,
When an ACL is added to Notes module, the attachments in the Notes are not affected by this ACL and anyone can view/download the attachments.
Can anyone solve it?
Regards
Hi
How did you add your ACL?
Did you run the 'Repair Roles' function?
Hi and thank you for your answer,
I add a role that affect the Notes module, some users can list the Notes but can't view it. The ACL for Notes work well, but not for the attachments in the Notes.
1.- In the Activities the users can list the notes and view the attachments in the Notes and can open/download the attached file bypassing the ACL.
2.- In other sections the users can list the notes but can view the attach icon, and click to open/download the file attached.
The attachments should not open.
Regards!
Hi
It's really look like an issueI could to reproduce it on my instance.
One solution that I see now is to place some tweak to download.php file.. I guess that some additional validation of ACL is needed there.
There are currently 1 users browsing this thread. (0 members and 1 guests)
Bookmarks