Capability

Security

Liferay DXP is built with security in mind. A variety of standards based authentication methods and integrations can be used to ensure secure access to a site and its resources. Robust role-based access control with permissions gives you fine grained control over what authenticated and unauthenticated users can access, share, or edit. Liferay DXP’s web services also have a multi-layered and configurable approach to security and authorization.

Feature
Deployment Approach
404 VIEW Permission Error occurs for Account Members API despite "View Users" Permission on the Account
Issue A 404 error code with status “NOT_FOUND” response is generated after making an API call to the "getAccountUserAccountsByExternalReferenceCodePage" endpoint. This occurs even if the caller has the “View Users” permission...
Guest unable to add entries to object longtext field
Issue Guest is uanble to add entries to a form containers. Steps to reproduce: Create an object with a custom field(say TestField) of type Long Text. Edit the custom field and add a limit of 500 and save this...
Portlet's title is shown instead of the web content's title
Issue The web content's title is not displaying. Steps to reproduce: Start server Create global web content Put a WCD on a page, select global scope, and display the web content in it Observed behavior: Portlet's...
'Questions' portlet not available in Type facet configuration
Issue  Unable to filter for "Questions" portlet in "Type Facet" configuration Environment Liferay DXP 7.3 Liferay DXP 7.4 Resolution This is intended behavior of Liferay Type Facet narrows search results down to...
The user can see the Required checkbox
Issue The required field from the data provider screen should be hidden Steps to Reproduce: Navigate to Content & Data -> Forms and click on the 'Data Providers' tab Click on + to create a new data provider...
Site navigation menu can't be edited
Issue We noticed that our site navigation menu is not editable anymore and it throws an error message and an exception in the logs when we open it: <Menu> is temporarily unavailable....
To be able to generate a URL of a Publication so that a reviewer can see a publication without logging in
Issue Require a feature that allows to send a link to those who are not registered users on the platform in order for them to view a publication. Environment Liferay DXP [all versions] Resolution This requirement...
There will be more than one default Transition in Kaleo workflow
Issue The user cannot set the first created Transition of a task to "default=false" and there will be more than one default Transition. Environment Liferay DXP 7.4  Resolution This behavior is a known bug of DXP...
Language Modules Configuration Display template not working properly
Issue Language Selector shows same template, if user selects a different display template. Steps to reproduce: 1. Start Liferay DXP 7.4. 2. Create a widget page. 3. Now, drop the 'language selector' widget on the...
cart total rule in discount portlet
Issue While publishing the Discount it's not showing as the cart total minimum account is required to fill. Steps to reproduce: 1. Start Liferay DXP 7.4. 2. Navigate to Discounts > Pricing > Commerce. 3. Click on...
Unable to view the updated content with 'View in Context' redirection link
Issue Users are unable to view the updated content on the page when clicking on 'View on Context'. Steps to reproduce: 1. Start Liferay DXP 7.4. 2. Assign the 'Single Approver Workflow' to the web content. 3....
"The requested resource could not be found" errors
Issue The requested resource could not be found errors can be observed with my profile and my dashboard or let's say users cannot access their own personal pages. Steps to reproduce: 1) Set up a clean instance of...
Losing CSS Client Extensions when navigating to different page settings tabs and saving
Issue CSS Client Extensions are being lost when navigating to a different tab in page settings and saving changes. This can be reproduced with the following steps Steps to reproduce Start a clean bundle of Liferay DXP...
Unable to add Relationships between the Account / Portal Address Object and Custom Object
Issue When trying to create a relationship between the Account or Portal Address system object and a custom object, it fails. Depending on the (wrong) setup, the user might receive the following error message in the...
No data is sent to Analytics Cloud after connecting to DXP
Issue We have connected our DXP instance to Analytics Cloud No data appears in AC, even after a few hours' wait   Environment Liferay DXP 7.0+ Analytics Cloud   Resolution Please access the DXP site from different...
When editing the code editor in the dispatch details tab, is it possible to register in JSON format?
Please be aware that the page you are viewing has been machine translated from Japanese into English and may contain some translation errors. If you observe any issues with the translation, please contact us....
Performing a search from System or Instance Settings throws an error exception
Issue When using the search bar in Control Panel for System Settings, Instance Settings, etc, an error exception is thrown and the UI presents the following message: “Portlet is temporarily unavailable" ”....
Lost in format texts when copying content from Google Docs
Issue When trying to copy content from Google Docs, it loses the format. Environment All environments. Resolution This is an expected behavior, unfortunately. The resolution is to customize CKEditor to detect...
How to disable the Asset Publisher's auto scroll
Issue I would like to disable the auto scroll of Asset Publisher. Is there any setting to do this? Environment Liferay DXP 7.2 Fix Pack 15+ Liferay DXP 7.3 Service Pack 3+ Resolution You can disable the Asset...
Is Liferay vulnerable to CVE-2023-40371 and CVE 2023-38408?
Issue Is Liferay vulnerable to any of these vulnerabilities? Environment DXP 6.2+ Resolution No, Liferay is not vulnerable to any of these two. Neither CVE relates to any Liferay features, so they do not...
Jenkins build fails with "Default Jenkinsfile not found"
Note: please note that Liferay has renamed its Liferay Experience Could offerings to Liferay SaaS (formerly LXC) and Liferay PaaS (formerly LXC-SM). Issue We updated our CI service's version after...
Automatic log rotation doesn't work
Note: please note that Liferay has renamed its Liferay Experience Could offerings to Liferay SaaS (formerly LXC) and Liferay PaaS (formerly LXC-SM). Issue We have updated our web service to...
Jenkins build fails with "LCP.json with id "undefined" is not valid against the schema" error
Note: please note that Liferay has renamed its Liferay Experience Could offerings to Liferay SaaS (formerly LXC) and Liferay PaaS (formerly LXC-SM). Issue Our new build is failing in Jenkins with the...
Is there any risk in the time zone change?
Issue We want to change the time Zone from GMT+2 to GMT+3. Does this change have any impact or risk on the production environment?   Environment Liferay DXP 7.2   Resolution Our suggestion is not to change...
'View in Context' link is not showing update content with display page template
Issue Users are unable to view the updated content on the page with the display page template when clicking on the 'View in Context' link on the Review page. Steps to reproduce: 1. Create a Page and deploy asset...
'web-content-name' is temporarily unavailable when trying to preview the content
Issue 'content is temporarily unavailable' when trying to preview pending content through the view icon on the Review Page. Steps to reproduce: 1. Start Liferay DXP 7.4. 2. Assign the single approver workflow to...
Unable to delete an Account entry
Issue When navigating to Control Panel > Accounts, an existing Account entry cannot be deleted successfully. This issue can occur when the “Account” system object has a relationship with an inactive object. Environment DXP...
The same page is displayed with different URLs in Analytics Cloud
Issue If you check the Top Pages chart in Analytics Cloud, you will see that the same page can be displayed with different URLs. Environment Liferay DXP 7.0+ Analytics Cloud Resolution Page metrics in AC are grouped...
How to navigate between sites while using the site virtualhost?
Issue User wishes to navigate between sites while accessing each site virtualhost.  Environment Liferay DXP 7.1 Liferay DXP 7.2 Liferay DXP 7.3 Liferay DXP 7.4 Resolution Create a site and add new page to...
How to search for the User's contact Phone Number?
Issue Is there a way to configure Liferay's default Search Bar to allow searching by a User's Phone Number defined in the Contact Information tab? Environment Liferay DXP 7.4 Resolution Liferay's default Search Bar...
How to test documentDownloaded and documentPreviewed events
Issue How can we test and confirm that the documentDownloaded and DocumentPreviewed events are getting tracked by Analytics Cloud? Environment Analytics Cloud Resolution After connecting Liferay DXP to Analytics Cloud, the...
Bug when switching to JDK 11.0.20 and Invalid CEN header
Issue We have discovered a bug in one of the tools that we use to publish artifacts leaving us with artifacts in our Nexus repositories/Maven Central with this bug. When users switch...
When we enable captcha in forms, it doesn't show up
Issue When we enable captcha in forms, it doesn't show up and below exception appears in the logs Caused by: java.lang.NullPointerException at...
How to verify the current Implementation version of log4j.jar file
Issue We would like to verify the implementation version of a log4j.jar file, either to verify the application of an update or to assess current vulnerability.  Environment DXP 7.3, DXP 7.4 Resolution You can find the...
Error concerning LDAPUserImporterImpl when importing data from LDAP onto Liferay
Issue  We encountered the following error when attempting to import user data from LDAP onto Liferay:   ERROR [liferay/scheduled_user_ldap_import-1][LDAPUserImporterImpl:817] Unable to import user CN=firstName...
How to delete old audit events 'audit_auditevent' table in 7.2+.
Issue I want to clean up the AUDIT_AUDITEVENT table in a 7.2+ instance, because the old data is taking up too much space. However, the API made after 7.2, and the previous methods of clearing the 'audit_auditevent' ...
Restrict drag and drop for multiple images in blogs
Issue Why is there no error or warning while selecting multiple images to upload via drag-and-drop functionality? If it is not uploading multiple images, then it should not select multiple images in the first...
Values added at source in web content are not working properly
Issue When the string '-' or any special character is written in the source code of web content, it should display the hyphen character or expected character on the display page Current Behavior: The page is not...
Discounts is temporarily unavailable errors in the case with any amount that does contain a comma
Issue The error arises when we use an amount split by a comma, such as 1000,00.00 Steps to reproduce: Create Discount Navigate to Rules Add Cart Total Rule Click that rule and go to the Edit page Add 1000,00.00...
Do video fragments support sites other than YouTube?
Issue There are 2 out-of-the-box fragments that support loading external videos: External Video Video URL Right now only a couple sites are supported, such as YouTube. When will the other sites, such as dailymotion, be...