I'm not sure the node permissions are being applied to editable fields?

Example:

For content type article, authenticated user role only has permission to edit own content. Content type article has an editable field.

User A creates an article node. User B can view the node and edit the field, even though he can't edit the node.

Comments

mr.h’s picture

Priority: Normal » Major

This is bad. I can also edit other user profiles

thechanceg’s picture

It doesn't look like it has any kind of permissions check. I can actually edit content without being logged in?!

q2_faith’s picture

+1

johnv’s picture

Taxoman’s picture

Status: Active » Closed (duplicate)