NOTE: If you are a developer, please use a private wiki based on foswiki/trunk on a daily base ...or use
trunk.foswiki.org to view this page for some minimal testing.
Use
Item9693 for docu changes for 1.2 and 2.0.
Item42: SECURITY: REVINFO reveals info for a topic the user does not have permission to view.
| Priority: |
CurrentState: |
AppliesTo: |
Component: |
WaitingFor: |
| Urgent |
Closed |
Engine |
|
|
--
SvenDowideit - 01 Nov 2008
REVINFO allowed recovery of revision information for a topic where the reader did not have view access. Note there is an argument that the viewer should at least be able to see
who made the edit. in the end I decided not to bother trying to suport that, though.
Added a check, unit tested.
--
CrawfordCurrie - 01 Dec 2008