Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-13923

Hidden and published blog articles should not be visible to users other than author and admins

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Minor
    • Resolution: Duplicate
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: None
    • Labels:
    • Difficulty:
      Unknown
    • Similar issues:

      Description

      Affected version: XWiki Enterprise 8.4 (Jetty HSQLDB all-in-one package). Steps to reproduce:
      1. Log in as Admin, post a blog entry (publish), click the Hide button (the small lock icon). The tool-tip now reads "This blog post is not visible to other users..."
      2. In another browser, log in as user. I can see the hidden post in both Activity Stream, Left Navigation Pane, and the Blog listing (/xwiki/bin/view/Blog/)
      Not only it is confusing, but also it gives the blog authors a false sense of security (even though security is of less importance for blog posts than for the wiki pages).

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              gdelhumeau Guillaume Delhumeau
              Reporter:
              ka50 Dung Hoang
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: