Lightning knowledge archived articles are visible to users with only 'read' permission on Knowledge
Knowledge , Lightning , Listviews
Last updated 2019-08-19 ·Reference W-5925196 ·Reported By 11 users
Summary
Archived articles are visible in Lightning Knowledge 'Archived Articles' list view and when querying as users with only 'Read' CRUD permission on Knowledge object.
Affected user's assigned profile and permission sets do not have 'Manage Articles' permission.
In Salesforce Classic this scenario does not occur because archived articles can only be viewed from 'Article Management' tab. Users without 'Manage Articles' permission have no access to 'Article Management' thus no access to archived articles.
Repro
1. Create a user whose assigned profile or permission set(s) only grant 'Read' access for Knowledge.
2. Login as the example user above and navigate to Knowledge (home) in Lightning's navigation menu items and select the standard 'Archived Articles' list view.
Actual Results: The user can see the Archived articles in list view and access them successfully.
Expected Results: Since the user doesn't have "Manage Articles" profile permission and only 'Read' on the Knowledge object, archived articles should not be accessible to them.
Workaround
None at this time.
NOTE: As a new feature in Winter '20, we currently plan to include two new permissions to control visibility to Draft and Archived Articles.
Is it Fixed?
Any unreleased services, features, statuses, or dates referenced in this or other public statements are not currently available and may not be delivered on time or at all. Customers who purchase our services should make their purchase decisions based upon features that are currently available.