Skip to content

It is possible to see and use "Publishing Channel" modal with only "view-only" access to a channel #3079

@jonboiser

Description

@jonboiser

Observed behavior

I went to this channel for which I am not an editor, but was still able to see the Publishing Modal and could even click it.

image

Expected behavior

Non-editors with view-only access should not see the modal and/or the stop button.

User-facing consequences

non-editors can see and possibly access publishing functionality they should not have.

Additional information

I observed this using my Administrator-level account. I did not try to check on this with a non-admin account.

I did not try to interact with the modal, so was not able to see if I had permissions on the backend to cancel the publishing task, etc.

Steps to reproduce the issue

  1. Get someone with a channel you are not an editor of to publish a new version
  2. Before the publishing task finishes, you go and view the channel edit link for that channel
  3. You should see the publishing modal

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions