[ 
https://issues.apache.org/jira/browse/SLING-3899?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Marius Petria updated SLING-3899:
---------------------------------
    Attachment: SLING-3899.1.diff

I just realized that packages were build with the calling user session. The 
user session should be used only to check privileges, but the actual content 
buliding should be done with the agent session.

> Access content for replication on behalf of the user that triggered the 
> replication
> -----------------------------------------------------------------------------------
>
>                 Key: SLING-3899
>                 URL: https://issues.apache.org/jira/browse/SLING-3899
>             Project: Sling
>          Issue Type: Improvement
>          Components: Replication
>            Reporter: Marius Petria
>            Assignee: Tommaso Teofili
>         Attachments: SLING-3899.1.diff, SLING-3899.diff
>
>
> Currently the content is accessed via an administrative session. We need to 
> pass a ResourceResolver via all APIs to ensure that the content is accessed 
> only be users that have the right.
> For rule triggered requests the actions should be done on the behalf of a 
> replication-service-user.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to