-
Bug
-
Resolution: Duplicate
-
Low
-
None
Summary
If public access is disabled and permissions are specified for anonymous access authenticated users that shouldn't have access to the space will inherit permissions.
Steps to Reproduce
- Specify permissions on a test space to administrators only.
- Do not enable pubic access but specify all permissions on anonymous access for the test space.
- Access the space with a user account that isn't an administrator.
Expected Results
Since anonymous access is disabled. Only administrators should be able to access the space.
Actual Results
Any authenticated confluence user can access the space as well as they have the same permissions as specified on anonymous access.
Workaround
Remove all permissions for public access (which is the default).
- duplicates
-
CONFSERVER-28946 Anonymous space permission allows non-permissioned groups to access space, when global permissions are set to prevent anonymous access
- Closed
- relates to
-
CONFSERVER-11553 Improve the explanations for Not Permitted error
- Gathering Interest
- Testing discovered
-
CONFSERVER-40487 If public is disabled public access space permissions should bet set to default.
- Closed