Details
-
Bug
-
Resolution: Fixed
-
Blocker
-
12.7-rc-1
-
Unit
-
Unknown
-
N/A
-
N/A
-
Description
I have set xwiki.authentication.group.allgroupimplicit=1 and removed all xobjects from the xwikiallgroup. Now today every user can see every site, regardless of the rights. (Not the admin parts. They are still hidden.)
In our default settings the XWikiAllGroup can view and comment every page. When needed, we remove the rights from spaces\pages to hide things. That does not work anymore.
In the picture: The rights - and XWikiAll can still see the pages\children.