Customers without permission can edit comments

XMLWordPrintable

    • 1
    • Severity 3 - Minor

      Summary

      When users without permission to edit comments get to a page with comments, they are able to see the option to edit, click on it and edit it. They can't save the content.

      If they are not able to edit comments, they should not be able to see this option or at least see a warning notifying this lack of permission, which doesn't happens since the application do not shows any warnings.

      On the documentation says they need Add Comment permission and says that admins on the space can edit comments, but doesn't clarify if is mandatory to be an admin in order to edit comments.

      Environment

      Confluence Cloud

      Steps to Reproduce

      1. Get to a page with a user without permission to edit comments
      2. You will be able to edit the comment
      3. When saving the page will be loading forever with a spinning animation.

      Expected Results

      User should not be able to see the option to edit it, or, a warning regarding which permission is necessary to edit comments.

      Actual Results

      The page just keeps loading and nothing happens.

      Workaround

      Place the JIRA Issue macro outside the expand macro.

              Assignee:
              Kai Chen
              Reporter:
              Paulo Miguel (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: