Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-19696

Disabled users can access and download attachments from wiki pages

    XMLWordPrintable

Details

    • Bug
    • Resolution: Invalid
    • Blocker
    • None
    • 14.3-rc-1
    • Old Core
    • Windows 11 Pro 64 bit, Chrome 101, using a local instance of XWiki 14.3 on MariaDB 10.6, Tomcat 9.0.62, Java 17 (Oracle)
    • Unknown
    • N/A
    • N/A

    Description

      STEPS TO REPRODUCE

      1. Login as Admin
      2. Create a page and upload some attachments on it
      3. Create an user (e.g. U1)
      4. Login as Admin
      5. Disable the user's account (from Administration or from the user's profile page)
      6. Login with the user U1
      7. In the upper right search box, search for the previously uploaded attachments' names
      8. Click on the suggestions

      EXPECTED RESULTS

      As the user's account is currently disabled, no search suggestions are displayed when searching.

      ACTUAL RESULTS

      The uploaded attachments are displayed as suggestions and they can be accessed/viewed by the disabled users, or downloaded.

      The issue couldn't be reproduced on XWiki 14.2.1, where the search suggestions are not displayed at all (instead there was a spinning wheel and an error message at the bottom of the page: Failed to retrieve suggestions: Forbidden).

      Attachments

        1. Disabled_Search_14_2_1.png
          52 kB
          Ilie Andriuta
        2. Disabled_Search_14_3.png
          43 kB
          Ilie Andriuta

        Issue Links

          Activity

            People

              surli Simon Urli
              iandriuta Ilie Andriuta
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: