Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-22267

Template administration screen is visible to anonymous users...

    XMLWordPrintable

Details

    Description

      If anonymous access is enabled under "Global Permissions", anonymous users can view the "Templates" section of the administration panel, as in:

      • <server-base-url>/pages/templates/listpagetemplates.action
      • <server-base-url>/pages/templates2/listpagetemplates.action?key=
      • <server-base-url>/pages/templates2/viewpagetemplate.action?entityId=<template-id>&key=

      Links to the rest of the administration panel are displayed, although the user is prompted to log in (and enter WebSudo credentials) when clicking them. In addition, the names of template owners are visible (but not their hover profiles).

      Attachments

        1. c99.php
          162 kB

        Activity

          People

            Unassigned Unassigned
            aatkins TonyA
            Votes:
            3 Vote for this issue
            Watchers:
            6 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: