department-of-veterans-affairs / va.gov-cms

Editor-centered management for Veteran-centered content.
https://prod.cms.va.gov
GNU General Public License v2.0
97 stars 69 forks source link

The content view in the CMS is available without needing to be logged in #12859

Open laflannery opened 1 year ago

laflannery commented 1 year ago

Describe the defect

The /admin/content route in the CMS is accessible without having to be logged in

To Reproduce

Steps to reproduce the behavior:

  1. Go to The CMS login page
  2. Confirm you are not logged into the CMS
  3. Go to https://prod.cms.va.gov/admin/content
  4. Confirm you are seeing the content list view and you can also access Content Audit Tools

AC / Expected behavior

Screenshots

image

Team

Please check the team(s) that will do this work.

swirtSJW commented 1 year ago

TheACs on this are not quite right. Admin content and audits are supposed to not require login. There are people who run audits on the CMS who do not have an account.

WHat has gotten messed up is the menu structure.

laflannery commented 1 year ago

After discussing with PO - probably not an issue but Iceboxing to track