dotCMS / dotCMS/core

File Asset locked site/folder field and Permissions Restriction

Open
#30,747 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

OKR : Customer Support Team : Falcon Type : Defect
Dominant language
Java
Stars
970
Forks
486
Avg merge
3d 33m
Merged PRs (30d)
170

Description

Parent Issue

No response

Problem Statement

When selecting the site/folder field for "file asset" in the content type properties, any attempt to save will not work and the field will revert back to "system host". This prevents users who do not have "all sites" permissions to add or edit content of this type.

Also, when a user of the above permissions attempts to filter the content search for the "file asset" type, they will be unable to view any content items.

This breaks the experience for use of file assets in many contexts for non "all sites" permissioned users.

Steps to Reproduce
  1. Try to change the file asset site/folder field in the content properties to demo. See it reverts back to system host
  2. Try to filter the content search to file as a limited user of only permissions for demo.dotcms.com (not all sites), see "file" is not available in the content search

Please see screen recording here

Acceptance Criteria

File Assets should be visible if the user is permissioned to see them whether they are filtered in the content search, or a custom content tool.

The file asset content type should be able to have the site or folder field set to other hosts if desired, not default back after updating to system host.

dotCMS Version

Current/demo

Proposed Objective

Core Features

Proposed Priority

Priority 1 - Show Stopper

External Links... Slack Conversations, Support Tickets, Figma Designs, etc.

No response

Assumptions & Initiation Needs

No response

Quality Assurance Notes & Workarounds

No response

Sub-Tasks & Estimates

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the file asset site/folder update in content type properties and the file asset filter in content search with a user limited to demo.dotcms.com. Trace both flows to identify where site permissions affect saving and visibility. Done means the field retains another host and permitted users can see file assets in content search and custom content tools.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
authorization, content, search
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.