-
Type:
Bug
-
Resolution: Unresolved
-
None
-
Affects Version/s: None
-
Component/s: MatchAnalysis & Pretranslation
-
High
-
None
-
None
-
Emptyshow more show less
Problem
The Match analysis action in the task overview is displayed even when the current user does not have the editorAnalysisTask frontend right. This makes it impossible to grant the action only to selected roles, for example PM/admin users, while hiding it from editor-only users.
The MatchAnalysis plugin dynamically adds the item and assigns action: 'editorAnalysisTask', but its visibility binding only evaluates the selected task's state. The item also invokes its own handler, so it does not use the standard ACL-aware task-action path. Removing editorAnalysisTask from the editor role therefore has no effect on this menu item.
The additional runtimeOptions.plugins.MatchAnalysis.enableAnalysisActionMenu setting does not provide role-specific control. It is customer configurable and currently only disables the item. Setting it to 0 consequently leaves a disabled menu entry and also affects PM/admin users who should retain access.
Solution
Make the dynamically injected MatchAnalysis task action respect the existing editorAnalysisTask ACL and the customer configuration independently.
- Before adding analysisActionItem, check Editor.app.authenticatedUser.isAllowed('editorAnalysisTask', task). Users without the right must not receive the menu item.
- Preserve the existing task-state visibility condition for users who have the right.
- When runtimeOptions.plugins.MatchAnalysis.enableAnalysisActionMenu is 0, hide the item completely. When it is 1, enable the applicable item without overriding task-state hiding.
- Do not change default ACL database assignments. Existing installation- and customer-specific ACL customizations must remain untouched.