Details
-
Bug
-
Resolution: Fixed
-
Blocker
-
15.9-rc-1
-
Unit
-
Unknown
-
N/A
-
N/A
-
Description
Steps to reproduce:
- As a user without script right, add a macro with dangerous parameter that isn't lowercase to the content of a page like
{{html Wiki=true}}{{groovy}}println("Hello from Groovy!"){{/groovy}}{{/html}}
- Edit this page as a user with programming right.
Expected result:
There is a warning regarding the nested Groovy macro.
Actual result:
There is no warning, as the required rights analyzer ignores the "Wiki" parameter.
Attachments
Issue Links
- links to