Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-14232

DeletedDocuments API checks the wrong rights

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 9.3
    • Fix Version/s: 9.4-rc-1
    • Component/s: Old Core
    • Labels:
      None
    • Difficulty:
      Unknown
    • Documentation:
      N/A
    • Documentation in Release Notes:
      N/A
    • Similar issues:

      Description

      Both DeletedDocument.canDelete and DeletedDocument.canUndelete check the admin right on the context document instead of the actual deleted document's location.

      Additionally, DeletedDocument.getDocument checks for (current context document) admin rights instead of simply relying on DeletedDocument.canUndelete.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                enygma Eduard Moraru
                Reporter:
                enygma Eduard Moraru
              • Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: