Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
1.10.x, 1.10.1, 1.11.x
-
None
Description
As reported on users:
The new 1.10 authz implementation doesn't correctly combine global rules such as [/foo] with repository rules such as [repo:/foo]. The result is that authz rules result grant less access in 1.10 than those same rules in 1.9.
Regression test added in https://svn.apache.org/r1835049