Access Controlled links
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Document Library |
New
|
Undecided
|
Unassigned |
Bug Description
The way access controlled document links work appears to have either changed or we have a bug. Let me explain...
I have uploaded a document to the training DL which has had group-access applied to it so that only members of the LDAP group called ISD can see the link. The link is pulled through onto devtrain as a cherry-picked link on a page at the following site - http://
Now, the problem we have is this; the link to the document should only appear to those with the appropriate authenticated credentials (i.e. members of the LDAP group called ISD)...
When you access devtrain.beds.ac.uk you have to login (using your usual login, authenticated against our LDAP server) so you are authenticated. Someone who is not in the ISD group was able to go to the stated address (above) and they could see the access-controlled document link (marked with a * to confirm it is access-controlled). The problem with this is that they shouldn't be able to see the DL link at all - it is not meant to display for them at all.
The curious thing is that when they click on the download link (pdf or text in this case) it then asks them for login credentials before it allows them to download. In this case, their credentials were refused so they couldn't download the document. This is not how it is meant to behave. The 'Access controlled' links used to work exactly as described, but now they don't.
Has someone made changes to this and how it behaves? We really need this to be working the way it was before. If this is a bug, it's a very precise one.
(I will try all of this out on devstaff as well to see if it behaves in the same way).
Does this happens in the Silva interface, or in the public interface ? There is a squid caching the page ?