Details
-
Bug
-
Resolution: Fixed
-
Critical
-
15.5-rc-1
-
None
-
Windows 11 Pro, Chrome 117, using a local instance of XWiki 15.5.2 on PostgreSQL 15, Tomcat 9.0.80
-
Unknown
-
N/A
-
N/A
-
Description
Steps to reproduce
- Login as Admin
- Create an user (e.g. U1)
- Login with the user
- Turn ON the Watch Notifications toggles to watch the whole wiki
- Login as Admin
- Go to Administer Wiki > Extensions > Security Vulnerabilities
- Insert a number in the Scan Delay field
- Click 'Save'
- Login as the user
- Observe the Notifications list
Expected results
There is no notification in the list about changing the configuration.
Actual results
The user get a notification for the Config page: http://localhost:8080/xwiki/bin/view/XWiki/Extension/Security/Code/Config.
Clicking on the event date from the notifications list to display the diff reveals No Changes, but on the notification received on email the diff is displayed (please see the attached screenshot).
However, the users don't have Edit right on the Config page.