Modify

Opened 16 years ago

#3480 new defect

ignores user privileges

Reported by: anonymous Owned by: RottenChester
Priority: normal Component: IncludePagesPlugin
Severity: major Keywords:
Cc: Trac Release: 0.11

Description

The macro allows a user with no WIKI_VIEW privileges to some page to include the page in an other page and thus gaining access to it, e.g. putting [[IncludePages(SomeRestrictedPage)]] in wiki:PubliclyAvailablePage? gives everyone reading access to SomeRestrictedPage through PubliclyAvailablePage.

I am using Trac 0.11b2.

Attachments (0)

Change History (0)

Modify Ticket

Change Properties
Set your email in Preferences
Action
as new The owner will remain RottenChester.

Add Comment


E-mail address and name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.