Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-13713

Guest user can still add/delete attachments using REST API when its denied edit right

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Critical
    • 7.4.5, 8.3-rc-1
    • 3.0
    • REST
    • None
    • Unknown
    • N/A
    • N/A

    Description

      Same for xobjects.

      Rest API use old right check API based on user string reference and when the user in the context is null it convert it to XWiki.Guest instead of XWiki.XWikiGuest...

      In indicated 3.0 but as far as I can see it always been like this so it's probably much older.

      Attachments

        Activity

          People

            tmortagne Thomas Mortagne
            tmortagne Thomas Mortagne
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: