Details
-
Bug
-
Resolution: Solved By
-
Critical
-
9.4-rc-1
-
Unknown
-
N/A
-
N/A
-
Description
Steps to reproduce:
- As admin, create a secret document and restrict access to admins (using the page administration).
- Again as admin, delete the secret document.
- As a simple user, re-create the secret document (or wait for an admin to re-create while being accessible). Edit it again to get at least two revisions.
- As simple user, open the diff view. Change the URL of one of the revisions to "deleted:1". Try increasing the "1" until it succeeds (for reproduction, look up the actual number in step 2, it is in the URL where you can view the deleted document).
Expected result:
No content of the deleted secret document is displayed.
Actual result:
The content of the deleted secret document is displayed in the diff.
Attachments
Issue Links
- depends on
-
XWIKI-20685 No extra right check in script API when accessing deleted documents
- Closed
- is duplicated by
-
XWIKI-20685 No extra right check in script API when accessing deleted documents
- Closed
- links to