Details
-
Type:
Bug
-
Status:
Closed
-
Priority:
Blocker
-
Resolution: Won't Fix
-
Affects Version/s: 3.1
-
Fix Version/s: None
-
Component/s: Old Core
-
Labels:None
-
keywords:rights, rights management
-
Difficulty:Unknown
-
Similar issues:
XWIKI-2410 Ability to filter users/groups by granted rights in the new Rights Management UI XWIKI-1915The new user, groups and rights management has some bugs in Firefox 3.0 beta1 XWIKI-1963Various bugs in the new Rights Management UI XWIKI-8Revamping of the Rights Management XWIKI-2016User rights management - ClassCastException with Oracle XWIKI-2403No error/warning displayed in the rights management UI when the user has forbid himself from editing XWIKI-2636 Make inherited rights visible in the Rights Management UI XWIKI-2068Rights Manager does not clean deleted user/group in all wikis XWIKI-171Complete User and Group Rights Management Documentation XWIKI-7521Setting explicit rights to particular user denies all existing group rights
Description
Two Default groups: XWikiAllGroup and XWikiAdminGroup
Admin gives rigths to XWikiAllGroup to view pages - no problem.
Admin gives rigths to XWikiAllGroup to EDIT pages.
User With Edit rights has possibiity to manage access rights.
I even tried to prohibit to XWikiAllGroup users Administration rights, nothing changed.
If "smart user" (e.g. "Test" in XWikiAllGroup) with edit rights will:
- prohibit access to pages to whole XWikiAllGroup OR
- grant VIEW rights ONLY
to XWikiAdminGroup
Then page becomes inaccessible to non-admin users. Test User can easily grant any right to admin
group. It gives an error, but actually sets right.
So, Test User can even grant himself delete rights on page, then delete page successfully even if delete right is BLOCKED for XWikiAllGroup.
Looks Dangerous.
Activity
Thomas Mortagne
made changes -
| Field | Original Value | New Value |
|---|---|---|
| Component/s | Old Core [ 11334 ] | |
| Component/s | Administration [ 10007 ] | |
| Component/s | Rights [ 11203 ] |
Andreas Jonsson
made changes -
| Assignee | Andreas Jonsson [ aj ] |
Andreas Jonsson
made changes -
| Status | Open [ 1 ] | In Progress [ 3 ] |
Andreas Jonsson
made changes -
| Status | In Progress [ 3 ] | Open [ 1 ] |
Andreas Jonsson
made changes -
| Status | Open [ 1 ] | Closed [ 6 ] |
| Resolution | Won't Fix [ 2 ] |
Andreas Jonsson
made changes -
| Link | This issue duplicates XWIKI-6946 [ XWIKI-6946 ] |