Uploaded image for project: '{RETIRED} XWiki Administration Application'
  1. {RETIRED} XWiki Administration Application
  2. XAADMINISTRATION-98

User that is not the Admin can restore pages deleted by admin

    XMLWordPrintable

Details

    • Bug
    • Resolution: Won't Fix
    • Major
    • None
    • 1.24
    • Users, Groups, Rights
    • None

    Description

      Steps to follow to reproduce:

      • log in as admin
      • create a page
      • delete the page
      • create a new user
      • log in as the new user
      • go to the page that has just been deleted by the Admin

      Result: You can restore the page deleted by the Admin while logged in as a normal user.

      Since the user did not create that page and doesn't have rights to delete it he shouldn't be able to restore it either.

      Notes:

      • This is particularly important for user profiles. A user that's not an admin cannot create/delete other users, so he shouldn't have the right to restore them either.
      • If you go to the "Document Index", to the "Deleted Documents" tab you can restore all docs

      Attachments

        Activity

          People

            sdumitriu Sergiu Dumitriu
            silvia.rusu Silvia Rusu
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: