Details
-
Improvement
-
Resolution: Fixed
-
Major
-
15.7
-
None
Description
See https://forum.xwiki.org/t/a-content-analysis-based-approach-for-required-rights/13094
Introduce an analyzer to detect the rights required by a document from its content and a user.
When user editing (or trying to edit) a document leads to a change in the required rights, a warning message is diplayed.
Attachments
Issue Links
- blocks
-
XWIKI-20331 RCE payloads stored in comments and profile are executed when admin user edits them.
- Closed
- causes
-
XWIKI-21798 The url to required rights entities are always the current page
- Closed
- is related to
-
XWIKI-21308 No warning when an in-place field from a page belonging to an extension is edited
- Open
-
XWIKI-21309 No warning when rollbacking a page belonging to an extension
- Open
-
XWIKI-20907 Introduce the notion of required rights
- Closed
-
XWIKI-21310 Generalize on the pre-edit document check
- Closed