Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-36687

Member of confluence-administrators group able to see restricted page in pagetree, quick search and navigation panel

    XMLWordPrintable

Details

    Description

      Bug Background

      Confluence super-users or member of confluence-administrators group should be able to access any content in Confluence including restricted content as long as it have the direct URL to access as describe in our documentation here


      The 'confluence-administrators' group defines a set of 'super-users' who can access the Confluence administration console and perform site-wide administration. Members of this group can also see the content of all pages and spaces in the Confluence instance, regardless of space permissions. They cannot immediately see the pages that exclude them via page restrictions without knowing the direct URL to the page. They can remove the page restrictions via the Space Administration screen if need be. For example, they will not see restricted pages displayed by the children macro. But they are able to access restricted pages directly using the page URL.

      The above documentation confirm that super-users should follow the following points:

      1. See all content of all pages and spaces in the Confluence instance.
      2. They cannot immediately see the pages that exclude them via page restrictions without knowing the direct URL to the page.
        • For example, they will not see restricted pages displayed by the children macro. But they are able to access restricted pages directly using the page URL.
      3. They can remove the page restrictions via the Space Administration screen if need be.

      The second point clearly describe that Confluence super-users can only access restricted page only through direct URL and no other method. We have confirmed that the following feature won't reveal restricted page to super-users

      • Search function
      • Recently-updated macro
      • Children Macro

      However the following features does not hide the restricted page as describe in the following screenshots:

      In this scenario, Restricted page is restricted for all user except for one user. However the following features still provide the link to this page to super-users

      • Navigation Panel in Default Theme
      • Page Tree
      • Quick Search

      Attachments

        1. navigation.png
          navigation.png
          49 kB
        2. pagetree.png
          pagetree.png
          10 kB
        3. quicksearch.png
          quicksearch.png
          20 kB

        Issue Links

          Activity

            People

              Unassigned Unassigned
              scahyadiputra Septa Cahyadiputra (Inactive)
              Votes:
              8 Vote for this issue
              Watchers:
              14 Start watching this issue

              Dates

                Created:
                Updated: