Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-20369

A user can access a space's PDF Layout/Stylesheets without global Confluence admin permissions.

    XMLWordPrintable

Details

    Description

      It was initially believed that a Confluence user account had to have some kind of Global Admin privilege to allow the editing of any space's PDF stylesheet/layout:

      If I log in to Confluence using an account with Space Administrator permissions for the ALLDOC space (but which has no Global Admin privileges), the two options above do not appear in the space's Space Administration area.

      However, if I log in with this same account, copy the URLs above and paste them into my browser window, I can access these stylesheets, edit their content and save it.

      We originally believed this lack of links on the space admin UI to be expected behaviour, due to a perceived risk of running malicious code in these text boxes (CONF-5808). Therefore, the fact that you could access these URLs (without Global Admin privileges) was believed to be a security risk - hence, the creation of this JAC issue. However...


      After discussing this with Ryan Ackley, there doesn't appear to be a security risk for the PDF stylesheet/layout templates. So, instead of restricting access to these functions to confluence administrators, these functions can be made available to space administrators as well.

      The fix is to re-enable the "PDF Layout" and "PDF Stylesheet" menu items if the user is a space administrator. The "Layout" and "Stylesheet" will continue to be restricted to confluence administrators (i.e. current behaviour).


      See Craig's comment on CONF-5808, which backs up this claim.

      Attachments

        Issue Links

          Activity

            People

              cpetchell Petch (Inactive)
              ggaskell Giles Gaskell [Atlassian]
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: