Details
-
Bug
-
Resolution: Duplicate
-
Major
-
None
-
4.1-rc-1
-
Unknown
-
N/A
-
N/A
-
Description
How to reproduce:
- have a space that has the WebPreferences page
- as admin, you delete the WebPreferences page or even the entire space
- non-admin users can restore the WebPreferences page
WebPreferences pages are a special case and they could contain harmful rights. Since only admins have the right to create/edit them, only admins should have the right to restore them.
Attachments
Issue Links
- duplicates
-
XWIKI-6946 A normal user can obtain space admin level by manually editing/creating WebPreferences in the object editor or programatically
-
- Closed
-