Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-12579

Unrendered velocity code in 'My Recent Modifications' panel when displaying pages that I don't have view rights anymore

    Details

    • Difficulty:
      Unknown
    • Documentation:
      N/A
    • Documentation in Release Notes:
      N/A
    • Similar issues:

      Description

      It's probably older than 7.2-RC1, but this is the version tested on.

      Steps:

      • Create/modify pages in A/B/C with a normal user;
      • Administrator will deny the VIEW right for the user for that pages;
      • The 'My Recent Modifications' panel still will display the changes, unrendered, see unrenderedModifications.png
      <ul>
        <li>
          <a href="$recentDoc.getURL()">$escapetool.xml($recentDoc.plainTitle)</a>
        </li>
      </ul>
      

      Expected: We should

      • not display the entries anymore or
      • display the name of the document, not as link, but as simple text;
      • or even as link, but the 'You are not allowed to view this page or perform this action.' will be displayed on that page.

        Attachments

          Activity

            People

            • Assignee:
              camil7 Clemens Robbenhaar
              Reporter:
              evalica Ecaterina Moraru (Valica)
            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:
                Date of First Response: