The Space sidebar contains a Create Page link even for users without the Add Page permission

XMLWordPrintable

    • Severity 3 - Minor

      Issue Summary

      The Space sidebar contains a Create page link even when the current user doesn't have the Add page permission.
      If that user clicks on that link, then a No Permission page is loaded with the wrong warning message.
      Even if a mail server is configured, this page won't load the Request Access button.

      Environment

      Fresh install of Confluence 6.12.0.
      It was confirmed on 6.6.3 as well.

      Steps to Reproduce

      Create a fresh install of Confluence Server and do the following as the admin:

      1. Add a new user (user001) to Confluence and make sure it is added only to the confluence-users group.
      2. Create a new space named Space A.
        • Add the View Space Permission and remove any other related to the confluence-users group.

      Access Confluence as user001:

      1. Access Space A home page and you will see the Create page link in the side bar.
      2. Click on the Create page link and the No Permission page is loaded with the wrong warning message.

      Expected Results

      1. If the user doesn't have the Add page permission, the Create page link doesn't appear in the sidebar.
      2. If the link must be there, then the No permission page should give a meaningful message saying the user doesn't have permission to create pages on that Space and should render the Request Access button if the mail server is enabled.

      Actual Results

      1. The user has access to a Create page link even when the Add page permission is not granted.
      2. Access the createpage.action link to a Space on which the user doesn't have the Add page permission shows a confusing message.
        • If the mail server is enabled, there's no Request Access button.

      Workaround

      None at this moment

        1. new_img_001.png
          new_img_001.png
          233 kB
        2. create_page_img001.png
          create_page_img001.png
          73 kB

            Assignee:
            Oliver Shen
            Reporter:
            Thiago Masutti (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: