Hello Sitefinity team
I am using Sitefiny 3.2 SP1
In a new test project I defined the following sitemap:
Home and Secure pages have Allow for the Anonymous access, Group1 and Group2 have Deny for Anonymous access.
Home and Secure pages inherit the permissions from the parent, for Group1 and Group2 the inheritance is broken.
Further I defined two roles: group1 with user1 added and group2 with user2 added.
The permission for Group1 page:
group1 has Allow permission, group2 deny permission
The permission for Group2 page:
group2 has Allow permission, group1 deny permission
On the Home page (default master and Blue with right sidebar theme) I added the Site menu control in the Top menu container and the Login control in the Content container.
When I am opening the Homepage of this test project, I am not logged in and see only Home and Secure menu's. This is correct.
When I am trying to open http://<server>/<cms test website>/ Secure/Group1.aspx
I am redirected to the login page. This is also correct.
When I am logging in as user1 (member of group1) I see the Home and Secure main menu items and Group1 submenu under Secure menu item. I don't see Group2 page under the Secure menu item. This is correct too.
However, the problem is that I am able now (as user1) to navigate to the http://<server>/<cms test website>/ Secure/Group2.aspx although I don't have the permission to, without any redirection to the login page.
Is this a bug or did I define the permissions in a wrong way?