Uploaded image for project: 'Confluence Cloud'
  1. Confluence Cloud
  2. CONFCLOUD-82492

Users Without "Restrictions Add/Delete" Permission AND Space Admin Rights Can Update Subfolder Restrictions

XMLWordPrintable

      Issue Summary

      Users lacking "Restrictions Add/Delete" permission and space admin rights can still update subfolder restrictions

      Preconditions: Ensure you have another user account, e.g., TestUser, who does not have "RestrictionsAdd/Delete" permission and is not a space admin from space settings.

      Steps to Reproduce

      1. In a Confluence space, create a parent folder under the space home page.
      2. Click on "... -> Share" in the page tree, change the setting from Open to Restricted, and set the "Can edit" restriction to yourself. Set the "Can view" restriction to another user, e.g., TestUser. Save the changes.
      3. Log in as TestUser and create a subfolder under the parent folder.
      4. Click on "... -> Share" for the subfolder in the page tree and attempt to update the restrictions (still logged in as TestUser).

      Expected Results

      TestUser should not be able to edit or update the subfolder restrictions.

      Actual Results

      TestUser is able to edit and update the subfolder restrictions.

      Workaround

      Currently there is no known workaround for this behavior. A workaround will be added here when available

              Unassigned Unassigned
              01626315efcb Tristan Chou [Atlassian Support]
              Votes:
              3 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: