Details
-
Bug
-
Resolution: Fixed
-
Major
-
8.4.5, 10.11.8, 11.3.1, 13.6-rc-1
-
None
-
Unknown
-
N/A
-
N/A
-
Description
XWIKI-16544 was supposed to handle it, but did not change much to the logic of the display code in practice.
Reproduction steps
- Have 2 users U1 and U2 like a page X
- With an admin, disable the view right of U1 by U2
- With user U2 visit the list of likers of page X (e.g., http://localhost:8080/xwiki/bin/view/Main/?viewer=likers)
Expected
Only U2 is listed, and U1 is filtered out.
Actual
An entry is displayed for U1 with a bad display (so it does not leak undesired information).