Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-13923

Hidden and published blog articles should not be visible to users other than author and admins

    XMLWordPrintable

Details

    • Bug
    • Resolution: Duplicate
    • Minor
    • None
    • None
    • None
    • Unknown

    Description

      Affected version: XWiki Enterprise 8.4 (Jetty HSQLDB all-in-one package). Steps to reproduce:
      1. Log in as Admin, post a blog entry (publish), click the Hide button (the small lock icon). The tool-tip now reads "This blog post is not visible to other users..."
      2. In another browser, log in as user. I can see the hidden post in both Activity Stream, Left Navigation Pane, and the Blog listing (/xwiki/bin/view/Blog/)
      Not only it is confusing, but also it gives the blog authors a false sense of security (even though security is of less importance for blog posts than for the wiki pages).

      Attachments

        Issue Links

          Activity

            People

              gdelhumeau Guillaume Delhumeau
              ka50 Dung Hoang
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: