TitleAuthentication Improperly Allowed on Windows XP
Date05-Sep-2006 23:31:08 EEST
Version2.4.38
SubmitterTS
Bug criticalityMediumBug
Browser versionFirefox 1.5
Bug statusClosedBug
PageProvider usedJDBCPageProvider
Servlet Containertomcat 5.5.17
Operating SystemAll
URLn/a
Java version1.5

Running JSPWiki on Windows XP, I had a page with this restriction:

[{ALLOW edit Admin}]
[{ALLOW view Admin}]
There is an Admin group which does *NOT* include user terry2. User terry2 is, however, able to access the page.

When deployed to Linux, terry2 was denied access. Logged out and logged back in again as terry2, and the access was allowed.

When deployed on a host provider, terry2 was denied access. Then discovered the ACL error, and changed it to:

[{ALLOW edit Admin}]
[{ALLOW view Authenticated}]

Then user terry2 had capability to view the page.


There is a possibility that this was related to a bug pre-2.4.48. Could you please check if you can duplicate this using the latest version?

-- JanneJalkanen


No response from bug reporter, closing the bug.

--HarryMetske

Add new attachment

Only authorized users are allowed to upload new attachments.
« This page (revision-4) was last changed on 21-Mar-2007 21:59 by HarryMetske