View Issue Details

IDProjectCategoryView StatusLast Update
0000256WackoWikipage rightspublic2012-02-22 18:23
Reporteradministrator Assigned ToTann San  
PriorityhighSeveritymajorReproducibilityalways
Status resolvedResolutionfixed 
Target Version5.0.betaFixed in Version5.0.beta 
Summary0000256: Comments inherit their ACL settings on subpages like a new page from the level above
DescriptionThis means if a page inside a cluster one level above is accessible with "*" but the comment is made on the page on the next level with "$" the comment inherits the "*" from the level above, this is desirable for new pages but not for comments!

LevelOne/LevelTwo
* / $
Comment on LevelTwo
*

This can expose accidentally the comment and the existence of a hidden cluster to the public via Last Comments and the RSS feed for Last Comments.
TagsNo tags attached.

Relationships

related to 0000412 resolvedadministrator set correct permissions for comments 
child of 0000160 resolvedTann San comments won't take the ACL settings of the page 

Activities

Tann San

2009-04-09 19:55

manager   ~0000631

Comments inheritted the read ACL from their associated pages parent, not the actual associated page. This has been changed so that comments receive the full set of ACLs that their parent page has. They are also updated when performing a cluster ACL change. Comments get their ACL updated whenever their parent pages ACL gets changed.

Issue History

Date Modified Username Field Change
2009-01-12 20:52 administrator New Issue
2009-01-12 20:52 administrator Status new => assigned
2009-01-12 20:52 administrator Assigned To => Tann San
2009-01-12 20:52 administrator Legacy => NEW
2009-04-09 19:55 Tann San Note Added: 0000631
2009-04-09 19:55 Tann San Status assigned => resolved
2009-04-09 19:55 Tann San Fixed in Version => 5.4.0
2009-04-09 19:55 Tann San Resolution open => fixed
2009-04-11 01:53 Tann San Fixed in Version 5.4.0 => 5.0.0
2009-10-13 15:58 administrator Target Version 5.0.0 => 5.0.beta
2009-10-13 16:03 administrator Fixed in Version 5.0.0 => 5.0.beta
2010-03-08 10:17 administrator Category Page rights => page rights
2012-02-22 18:19 administrator Relationship added child of 0000160
2012-02-22 18:20 administrator Relationship added related to 0000412
2012-02-22 18:23 administrator View Status private => public