At some places the acl roles are checked directly. This must be changed to use ACL rights (which are composed to roles) instead.
Example beneath the comment in the screenshot: