-
Bug
-
Resolution: Fixed
-
High
-
2.1.3
-
Severity 3 - Minor
-
NOTE: This bug report is for Confluence Server. Using Confluence Cloud? See the corresponding bug report.
Problem Summary
Users are able to edit any Space Questions as long as they have View permissions for that space. This includes questions asked by other users. Users do not need to have Space Admin or even Add/Edit Page permissions to the space, only View is required.
This is inconsistent when compared to global questions (not tied to any specific space) which require either Confluence Administrator permissions or specific permissions granted based on CQ points levels. (Source: https://confluence.atlassian.com/display/QUESTIONS/Permissions)
Steps to reproduce
- Environment: Tested with Confluence 5.7.1 + Confluence Questions 2.1.3.
- Create a question in a Space
- Log in as a different user with only View permissions to that space, and navigate to the question
Expected behavior
The user will be able to view, but not modify, the question
Actual behavior
The Edit option will be present, and functional, for this user
[CONFSERVER-46923] Users with only View Space permission are able to edit Space Questions
Workflow | Original: JAC Bug Workflow v3 [ 2901428 ] | New: CONFSERVER Bug Workflow v4 [ 2996060 ] |
Workflow | Original: JAC Bug Workflow v2 [ 2797660 ] | New: JAC Bug Workflow v3 [ 2901428 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: JAC Bug Workflow [ 2718992 ] | New: JAC Bug Workflow v2 [ 2797660 ] |
Symptom Severity | Original: Minor [ 14432 ] | New: Severity 3 - Minor [ 15832 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2387054 ] | New: JAC Bug Workflow [ 2718992 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 [ 2284318 ] | New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2387054 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2224572 ] | New: Confluence Workflow - Public Facing - Restricted v5 [ 2284318 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2178300 ] | New: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2224572 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 [ 1943851 ] | New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2178300 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v3 [ 1740582 ] | New: Confluence Workflow - Public Facing - Restricted v5 [ 1943851 ] |