A back-end user who does not have the right to edit or view articles of a category can see this category in the drop-down "Select Category" list from "Search Tools" in the Content Manager, it can also be seen in "Batch".
Hide unauthorized categories from the Search Tools and Batch.
Unauthorized categories are showed
When writing a new article, only authorized categories are displayed, this situation should be the same for the search tool and batch
Status | New | ⇒ | Confirmed |
Hello, is it planned to fix this ? i'm not a coder but if i can help.
Shteevy.
non coder users can always help testing Pull Requests (PR).
At the moment there are more than 300 that needs tests https://github.com/joomla/joomla-cms/pulls
All Pull Requests need at least:
1. A volunteer contributor wiling to submit a PR with code
2. Two tests by other users
3. Be merged into the core by the mantainers
In this case, we don't have 1.
yet
willing to test if PR is submitted.
Status | Confirmed | ⇒ | Information Required |
set Status on "Information Required".
Hello,
I tried with 3.7.3-dev but I still can see unauthorized categories in the Search Tools and in the batch tools.
Steve.
That's a weird one. Please could you detailed the Steps to reproduce the issue that you are applying to see unauthorized categories?
Then I will test it a third time ;-)
Hello,
Here is the procedure to reproduce the issue with J! 3.7.2
The user is in a group authorized to create, delete, modify, modify status and modify own elements for only one category called "Valves (Pédagogique Mons)".
When the user is connected to backend and using the Search Tool (Content > Article > Search Tool), all the categories are showed into the dropdown menu.
The showed categories have the access right "Registered" but the user has not the right to publish into them.
Why are they showed ?
I have the same problem into "Batch Tool"
Many thanks,
Steve
@rvbgnu could you reproduce Issue?
Sorry for the late reply.
I could reproduce the issue, but I'm not sure if it is one actually!!
Please @shteevy I need more details of your user groups structure and categories permissions: this is a use case that we must checked.
For my test, using the latest joomla-3.7.4-dev with sample data, I created a Group with Manager as parent, to grant the specific user access to the backend, he/she automatically inherits permissions for all the categories.
So with more details, we could better reproduce the same issue. You could use Advanced Permissions Report in the group view to check like this:
Hello,
Sorry for this late reply too :)
The Group used for this test is a subgroup of "Public"
I remark that the user can see the categories with a "Registered" level access.
This group don't have the right to write, modify or delete in these categories. It should not see these categories into Search Tools and Batch Tools. Am i wrong ?
Screenshot of the global rights of this group :
Screenshot of the rights (with ACL Manager) of this group :
Screenshot of the access rights of these categories :
Have a nice day,
Steve
If this Issue get no Response, it will be closed at 17th September 2017.
Status | Information Required | ⇒ | Closed |
Closed_Date | 0000-00-00 00:00:00 | ⇒ | 2017-09-17 06:06:36 |
Closed_By | ⇒ | franz-wohlkoenig |
Set to "closed" on behalf of @franz-wohlkoenig by The JTracker Application at issues.joomla.org/joomla-cms/10802
This has been closed due to lack of response to the requests above – it can always be reopened .
Confirmed
This comment was created with the J!Tracker Application at issues.joomla.org/joomla-cms/10802.