Details
-
Bug
-
Resolution: Fixed
-
Major
-
5.4.5
-
None
-
Unit
-
High
-
Easy
-
N/A
-
N/A
-
Description
Currently the sheet displayer sets the content author of the displayed document to the content author of the sheet in order to preserve the PR of the sheet. We can do better by simply setting the sheet as sdoc (security document) which is used to check PR.
Attachments
Issue Links
- is related to
-
XWIKI-5027 In Syntax xwiki/2.x, programming rights may be inherited by inclusion which may leads to security issues
- Closed
-
XWIKI-7941 PR leak in sheets when displaying TextArea properties
- Closed
-
XWIKI-11223 Avoid hacking the context document content author by using XWikiContext sdoc hidden property in wiki macros
- Closed
-
XWIKI-11226 XWikiDocument context document switch shoud take into account secure doc (sdoc)
- Closed
- relates to
-
XWIKI-11235 Use the sdoc XWikiContext property instead of hacking the content author when switching WYSIWYG editor tabs
- Closed