Browse Behavior is Incorrect When the Browse Access Right is Denied on the Root Folder.

November 23, 2004 | KB: 1000797
Laserfiche 6.12, Plus 6.12

Summary

Security may not behave properly when the Browse access right is denied on the root folder. This type of configuration may prevent authorized users from browsing to folders they should be able to see and unauthorized users may be able to see the existence of folders that should be secured. This issue affects version 6.12 of the Laserfiche Server.

Note: Although unauthorized users may be able to see the existence of secured folders, they cannot open and view the contents of those secured folders.

Resolution

To resolve this issue, please upgrade to Laserfiche 6.12 (build 352) or later.

Workaround

This issue arises when you deny the Browse access right on the root folder and grant additional rights on child objects. Avoid this issue by changing your security configuration to the following:

  1. Grant the Browse access right on the root folder to all users.
  2. For each user/group that should have restricted access, deny the Browse access right on child objects (folders and/or documents).