-
Bug
-
Resolution: Duplicate
-
High
-
None
-
5.9.3
-
Severity 3 - Minor
-
1
-
We noticed that there is an issue with the security of pages in the blog feed. When the correct page restriction is set prior to saving a blog post, there is no issue. However, in can you save the blog post without setting the page restrictions, and you set these restrictions afterwards, the blog post is still visible on the blog feed.
In case a user that has no access to this particular blog post clicks on it, he gets a message stating "You do not have permission to view this page. Request access below, you will receive an email when you've been granted access.".
If you go to the blog instead of the blog feed the page restrictions are applied correctly, restricted pages are hidden from the tree in case the logged in user doesn't have the correct access rights (no issue here).
- duplicates
-
CONFSERVER-43311 Blog post macro should not display blog posts which are restricted.
- Closed
- relates to
-
CONFSERVER-40833 Deleted Pages, Blogpost and Attachments Returning in Confluence Search Results
- Closed
-
CONFSERVER-43311 Blog post macro should not display blog posts which are restricted.
- Closed