Details
-
Bug
-
Resolution: Fixed
-
Blocker
-
5.4.5
-
None
-
Unknown
-
N/A
-
N/A
-
Description
1. Log in with a user not having PR
2. Go to any page edited by Admin. ex: http://www.xwiki.org/xwiki/bin/edit/Main/SpaceIndex?editor=wysiwyg
3. Use the Source tab and paste:
{{velocity}} $doc.getDocument().class {{/velocity}}
4. Click back to the WYSIWYG tab
5. See the internal document
Use case:
- execute the code of XWiki.ResetPassword in a Blog post to change the password of any user