TitleAttachment viewable by any through the find (and contents) regardless of ACL of Parent
Date17-Apr-2006 19:32:24 EEST
VersionJSPWiki v2.3.92-alpha
SubmitterBruce E Hayward
Bug criticalityMediumBug
Browser versionIE 6 and Firefox
Bug statusClosedBug
PageProvider used
Servlet Containerjakarta-tomcat
Operating SystemSunOS web1 5.9 Generic_117172-05 i86pc i386 i86pc
Java version5.0.29

Basically when I do a find for a set of files, included in the results are some of the attachments stored on the site (uploaded into pages). I do not have access to the pages that they have been uploaded to, but can open the attachments (e.g. .txt ones for example) by simply clicking on the hyperlink from the returned results.

I am presuming that the attachments should have the same ACL as the document that they are uploaded into?


Yes, the permissions should inherit. Certainly a bug...

-- JanneJalkanen

Checked: This behaviour is gone in the latest version (2.3.104). Attachments inherit ACLs of the parent page.

-- JanneJalkanen

Wonderfull - Thanks

--Bruce E Hayward, 27-Jun-2006

Add new attachment

Only authorized users are allowed to upload new attachments.
« This page (revision-18) was last changed on 27-Sep-2006 21:32 by NascifAbousalhNeto