-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Low
-
Affects Version/s: 9.0.3
-
Component/s: User - Global / Space Permissions
-
6
-
Severity 3 - Minor
-
13
Issue Summary
This is reproducible on Data Center: yes
Steps to Reproduce
- Create a fresh Confluence instance
- Create a page, and obtain the Tiny Link for it
- Set Up Public Access
- Go to Administration > General Configuration > Global permissions.
- Choose Edit Permissions.
- In the Anonymous Access section, select the Can use checkbox. You can also choose whether to allow anonymous users to see user profiles.
- Choose Save All.
- Logout of Confluence and test the Tiny Link to see if it can be accessed anonymously.
Expected Results
Accessing the Tiny Link will open the anonymously accessible page without requiring a login.
Actual Results
A login page is displayed and the following, potentially related WARN, is logged in the atlassian-confluence.log file:
2024-09-10 15:58:10,694 WARN [http-nio-8090-exec-14 url: /pages/tinyurl.action] [webapp.security.enforcer.AnnotatedAccessEnforcer] shouldEnforce Access check is failed. Skipping Struts action com.atlassian.confluence.pages.actions.TinyUrlAction on method execute -- url: /pages/tinyurl.action | userName: anonymous | traceId: da26317c97f2c878
Workaround
Currently there is no known workaround for this behavior. A workaround will be added here when available
- mentioned in
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...
-
Page Loading...