Details
-
Bug
-
Status: Closed
-
Critical
-
Resolution: Fixed
-
2.10.2, 2.10.3
-
None
Description
Just set jspwiki.usePageCache to false, and find out (by accident) that ACLs are not taken into account anymore, leading to a major leak of information from pages that were not supposed to be viewable.
Attachments
Issue Links
- duplicates
-
JSPWIKI-1067 View-only ACLs are not enforced
- Closed
- is duplicated by
-
JSPWIKI-1047 Access Control Lists do not work if page cache is deactivated
- Closed