Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-8521

Admin can view a page, which is restricted to them by typing in the url to that page.

    • Icon: Bug Bug
    • Resolution: Won't Fix
    • Icon: High High
    • None
    • 2.5
    • None
    • Standalone Solaris 10 Unix with JDK 1.5

      When a group sets the permissions on a page to view and edit only for that group, the admin can view the page by typing in the url. This should not be the case. Many gourps want to post secure information and not allow the admin to view it.

      Knowing that the admin could remove the restrictions on the page and view the page is OK since we know that this could be detected. But the ability for them to type in the url to a page and view it isn't acceptable.

      I assume this affects all versions that allow page restrictions.

            [CONFSERVER-8521] Admin can view a page, which is restricted to them by typing in the url to that page.

            Agnes Ro added a comment -

            Unfortunately, this is a consequence of the implementation of the 'superuser' capabilities of the confluence-administrators group. There are plans to re-organise this part of Confluence, but at the moment administrator users can access restricted pages by typing in the url to the page. This problem only applies to a Confluence administrator, not space administrators.

            A space administrator cannot directly see restricted pages, but she can remove the restrictions within her space on the Space Admin tab of the Browse Space page.

            Please watch and vote for CONF-4616 which would fix this problem.

            Agnes.

            Agnes Ro added a comment - Unfortunately, this is a consequence of the implementation of the 'superuser' capabilities of the confluence-administrators group. There are plans to re-organise this part of Confluence, but at the moment administrator users can access restricted pages by typing in the url to the page. This problem only applies to a Confluence administrator, not space administrators. A space administrator cannot directly see restricted pages, but she can remove the restrictions within her space on the Space Admin tab of the Browse Space page. Please watch and vote for CONF-4616 which would fix this problem. Agnes.

              Unassigned Unassigned
              efe4717defd2 Matt Klein
              Affected customers:
              0 This affects my team
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: