Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-13717

Global user may loose local subwiki rights received via global groups

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Blocker
    • Resolution: Fixed
    • Affects Version/s: 7.1.4, 7.4.4, 8.2.1, 8.3-milestone-2
    • Fix Version/s: 7.4.5, 8.3-rc-1
    • Component/s: Security
    • Labels:
      None
    • Difficulty:
      Unknown
    • Documentation:
      N/A
    • Documentation in Release Notes:
      N/A
    • Similar issues:

      Description

      Steps to reproduce:

      • Create a global user test in a global group test
      • Create a subwiki, and put the global group test as a member of the local XWikiAdminGroup
      • At this stage, user test is admin of the subwiki
      • Save the XWiki.Preferences page of the subwiki (should clear the subwiki cache), or change the members of the subwiki XWikiAdminGroup
      • Now the test user has no more admin rights on the subwiki (fully if cache cleared, or only new evaluation if just admin group changed)

        Attachments

          Activity

            People

            • Assignee:
              softec Denis Gervalle
              Reporter:
              softec Denis Gervalle
            • Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:
                Date of First Response: