create new tag
, view all tags

Bug: ALLOWTOPICVIEW only restricts current revision

Using partial authentication, setting all ALLOW* variables in a topic only seems to restrict access to the current version of that topic. When a newer version of the topic is saved, anybody with view permissions on that web can view previous revisions of the topic that is supposed to be restricted from their view.

Test case

  • Create a "Restricted" web with all ALLOW* preferences set to a RestrictedGroup (which contains UserOne and UserTwo).
  • Create a topic Restricted.UserOnePrivate and set ALLOW* = UserOne.
    • Set ALLOWTOPICVIEW = UserOne
  • Login as UserTwo
  • Successful Tests (No permission to read topic ...)
    • attempt to view Restricted.UserOnePrivate
    • attempt to view Restricted.UserOnePrivate?rev=<current revision>
  • Failing Tests (able to view Restricted.UserOnePrivate as UserTwo)
    • attempt to view Restricted.UserOnePrivate?rev=<any previous revision>

NOTE: Index and Search seem to be restricting access appropriately in this testcase.


TWiki version: TWikiRelease02Sep2004
TWiki plugins: DefaultPlugin, SpreadSheetPlugin, ActionTrackerPlugin, CommentPlugin, EditTablePlugin, InterwikiPlugin, RenderListPlugin, SlideShowPlugin, SmiliesPlugin, TablePlugin
Server OS: Linux kernel 2.4.21-20.0.1.ELsmp
Web server: Apache/1.3.29
Perl version: 5.8.0
Client OS: MS Windows XP Pro, SP2
Web Browser: MS IE 6.0

-- RobKirk - 31 Dec 2004

Follow up

See related issue Support.ViewToViewauthNotWorking

-- PeterThoeny - 25 Jan 2005

Fix record

see proposal ...

-- ThomasBurgstaller - 17 Jan 2005

Edit | Attach | Watch | Print version | History: r5 < r4 < r3 < r2 < r1 | Backlinks | Raw View | Raw edit | More topic actions
Topic revision: r5 - 2005-01-25 - PeterThoeny
  • Learn about TWiki  
  • Download TWiki
This site is powered by the TWiki collaboration platform Powered by Perl Hosted by OICcam.com Ideas, requests, problems regarding TWiki? Send feedback. Ask community in the support forum.
Copyright © 1999-2018 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.