-
Type: Sub-task
-
Status: Closed (View Workflow)
-
Priority: Critical
-
Resolution: Fixed
-
Affects Version/s: 0.16 swallows
-
Fix Version/s: 0.18 Swallows, 1.5 Swallows, 1.4 Swallows
We have to check whether the user has specific permissions in order to log him in:
- User should be assigned with at least one component in the ACL. She should have admin rights for the component. You can figure this out by looking at what groups this user is in: if she is present in a group that has admin rights on the component, then she can be logged in.
- Some Spring Security researches should be carried out - we need to find a place where it's better to check for ACL permissions.
- relates to
-
POULPE-310 It is possible to login in poulpe without activation
- Closed