Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-6461

Can see other Users Profile/Personal Spaces hybrid in Recently Updated even if you dont have permissions to view them.

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Medium
    • 2.4.5
    • 2.2.2
    • None
    • Confluence 2.2.2 #516 (Security Patch applied)
      Linux
      JBOSS

    Description

      The Recently Updated section on the Dashboard exhibits buggy behavior with regard to users.

      If a user has a personal space, but the logged in user does not have permissions to see it, the user will still appear in the "Recently Updated" list.
      The link points to the personal space.
      Clicking on the link will go to a page with a Permissions error.
      However, the date listed is in the past, and is (I suspect) the date the user last edited their profile.

      It seems to me that ideally, if a viewer can not access a users personal space, the user should not be in the "Recently Updated" list at all.

      I have seen http://jira.atlassian.com/browse/CONF-6158 but i think this issue is subtly different - in this case maybe its users who previously had a profile?

      Attachments

        Issue Links

          Activity

            People

              mjensen m@ (Inactive)
              266cf4eaf355 James B
              Votes:
              3 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: