-
Bug
-
Resolution: Fixed
-
High
-
2.1.3
-
Severity 3 - Minor
-
NOTE: This bug report is for Confluence Server. Using Confluence Cloud? See the corresponding bug report.
Problem Summary
Users are able to edit any Space Questions as long as they have View permissions for that space. This includes questions asked by other users. Users do not need to have Space Admin or even Add/Edit Page permissions to the space, only View is required.
This is inconsistent when compared to global questions (not tied to any specific space) which require either Confluence Administrator permissions or specific permissions granted based on CQ points levels. (Source: https://confluence.atlassian.com/display/QUESTIONS/Permissions)
Steps to reproduce
- Environment: Tested with Confluence 5.7.1 + Confluence Questions 2.1.3.
- Create a question in a Space
- Log in as a different user with only View permissions to that space, and navigate to the question
Expected behavior
The user will be able to view, but not modify, the question
Actual behavior
The Edit option will be present, and functional, for this user