-
Bug
-
Resolution: Fixed
-
High
-
None
-
6.0.1
-
1
-
Severity 2 - Major
-
Summary
Members of the Confluence Administrators group are able to edit pages they don't have permission to. In addition, when attempting to edit a page without permissions, clicking Close results in a blank page.
Steps to Reproduce
- Make User A as the member of confluence-administrators group
- User A creates a space and makes User B the only Space Administrator
- User A goes to the page and the edit function is enabled
- User A Clicks Edit and starts to make changes
- User A finishes making changes to the page and clicks Save (which is enabled)
Expected Results
User A should not be able to edit the page.
Actual Results
- User A's changes are saved
- User A gets blank page below main Confluence top navigation bar when clicking Close after entering editor
Workaround
There are a few workarounds to this:
- Most importantly, Atlassian recommends not using your administration account for regular use of Confluence. Create separate admin and user accounts instead.
- Until CONF-4616 is fixed, grant administrators "System Administration" permission but do not put them in the "confluence-administrators" group if you do not wish them to have access to all content in your system. (This is in relation to the original bug.)
- duplicates
-
CONFSERVER-45289 Edit restricted page in Confluence as administrator (with Collaborative Editing enabled) resulted in a blank page.
- Closed
- is related to
-
CONFSERVER-25210 "Not Permitted" page when members of confluence-administrators attempt to edit pages on which they do not have edit permission
- Closed
-
CONFSERVER-43952 "Not Permitted" error on page refresh using Collab Editing
- Closed