Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-12570

Access right doesn't work well with subgroups

    XMLWordPrintable

Details

    • Bug
    • Resolution: Duplicate
    • Critical
    • None
    • 7.0.1
    • Security
    • Hard

    Description

      Hello,
      I found a bug with right access.

      I use LDAP authentication and xwiki local groups
      Everyone (in LDAP directory) can read all my xwiki but only XWiki.XWikiEditeurs have write access on a space Encyclopédie.

      XWiki.XWikiEditeurs contains some groups:

      • XWiki.GF_PiloteM2 (XWiki.xwikilecteur user in it)
      • XWiki.GF_CacP3 (XWiki.xwikilecteur user in it)
      • XWiki.GF_xxx (XWiki.xwikilecteur user is NOT inside)
        this sub groups contains users.

      Sometimes users of XWiki.GF_PiloteM2 and XWiki.GF_CacP3 lose write access on Encyclopédie (I didn't found the cause).
      When this happen, I found a way to fix this write access problem:
      I simply remove XWiki.xwikilecteur from a subgroup AND I replace him in same subgroups!!!
      It is clearely a bug, isn't it?

      XWiki.xwikilecteur is in this groups:

      • GF_PiloteM2
      • GF_CacP3
      • XWikiAllGroup

      and Encyclopédie space have this right access:

      • XWikiAllGroup: read/comment
      • XWikiEditeurs : read/comment/write
        XWikiEditeursEffac: read/comment/write/delete

      Thxs.

      Attachments

        1. Encyclo_APage_OKWrite.pdf
          89 kB
          Pascal BASTIEN
        2. Encyclo_WebHome_OKWrite.pdf
          89 kB
          Pascal BASTIEN
        3. EncycloWebHome_noWrite.pdf
          89 kB
          Pascal BASTIEN
        4. EncycloWebHomeKO.png
          57 kB
          Pascal BASTIEN
        5. EncycloWebHomeOK.png
          58 kB
          Pascal BASTIEN
        6. patch.txt
          2 kB
          Guillaume Delhumeau
        7. removeCacheEntry.txt
          0.3 kB
          Guillaume Delhumeau
        8. Sandbox.CheckSecurity.xar
          2 kB
          Denis Gervalle

        Issue Links

          Activity

            People

              softec Denis Gervalle
              Pbas Pascal BASTIEN
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: