Issue
Facing issues while using 'View' only permissions for 'Custom Field', able to see and even edit the details even after View only permission.
-
Steps to reproduce:
1. Navigate to Control Panel > Roles, and create a custom regular role, with the permissions attached in the snapshot.
2. Navigate to Control Panel > Users and Organizations, create a new user (say Test1), and assign the role, that was created in 1st step.
3. Navigate to Control Panel > Configuration > Custom Fields and create a few custom Fields inside any asset.
4. Now, Login using the 'Test1' user, and try to view the created custom Field.
- Observed Behavior: The user is able to view and even Edit the Summary, and see other configuration options as well which must be restricted for the user. However, while trying to save the changes, it redirects to previous screen without any error or info, and the changes are not saved.
- Expected Behavior: The user should not be able to view the configuration, and should not be able to edit the summary.
Environment
- Liferay DXP 7.3 fix-pack-dxp-2
Resolution
- The observed behavior is a known bug that has been addressed by: LPD-24354.
- Based on the LPS, this issue has been fixed in Liferay DXP 2024.Q1.8 and the above releases.
- If a hotfix is required or any more information on this, please create a support ticket requesting a hotfix by attaching patch details.
- Installing Fix Packs and Hotfixes on Liferay DXP will guide you to install this hotfix in the respective environment.