Opened 8 years ago

#3480 new defect

ignores user privileges

Reported by: anonymous Owned by: Rottenchester
Priority: normal Component: IncludePagesPlugin
Severity: major Keywords:
Cc: Trac Release: 0.11


The macro allows a user with no WIKI_VIEW privileges to some page to include the page in an other page and thus gaining access to it, e.g. putting [[IncludePages(SomeRestrictedPage)]] in wiki:PubliclyAvailablePage? gives everyone reading access to SomeRestrictedPage through PubliclyAvailablePage.

I am using Trac 0.11b2.

Attachments (0)

Change History (0)

Add Comment

Modify Ticket

as new The owner will remain Rottenchester.

E-mail address and user name can be saved in the Preferences.

Note: See TracTickets for help on using tickets.