Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-40908

Inconsistency in page security in blog feed

    XMLWordPrintable

Details

    Description

      We noticed that there is an issue with the security of pages in the blog feed. When the correct page restriction is set prior to saving a blog post, there is no issue. However, in can you save the blog post without setting the page restrictions, and you set these restrictions afterwards, the blog post is still visible on the blog feed.

      In case a user that has no access to this particular blog post clicks on it, he gets a message stating "You do not have permission to view this page. Request access below, you will receive an email when you've been granted access.".

      If you go to the blog instead of the blog feed the page restrictions are applied correctly, restricted pages are hidden from the tree in case the logged in user doesn't have the correct access rights (no issue here).

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              95eca6e4f6cd wim baert
              Votes:
              16 Vote for this issue
              Watchers:
              14 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: