Sharepoint 2007 SP1 - Security Exposure of Form Library

Recently we have launched a SharePoint application based on InfoPath forms. The functionality is very simple: the user creates browser-enabled InfoPath forms and an event receiver of the form library sets specific permissions. The security trimming works as expected so the forms’ owner is able to see only his forms. In production we found out that the form security behaves differently when accessing it by typing the URL in browser. It looks like the security permissions are ignored when the form item is open by typing the URL in browser.

The problem is fixed in SP2 so if you have a similar scenario as the one described above in one of your SharePoint application it will be a good idea to plan and install SP2 ;)

15 comments to Sharepoint 2007 SP1 – Security Exposure of Form Library

Leave a Reply

 

 

 

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comment Spam Protection by WP-SpamFree