Ticket #1677 (closed defect: fixed)
Wiki diff and history allowed without WIKI_VIEW permission
| Reported by: | anonymous | Owned by: | jonas |
|---|---|---|---|
| Priority: | high | Milestone: | 0.9 |
| Component: | wiki system | Version: | 0.8.2 |
| Severity: | major | Keywords: | permission |
| Cc: |
Description
A user (e.g. anonymous) with absolutely no WIKI_XXXX permissions can still access the history and diffs of wiki pages via...
http://.../trac/wiki/WikiPage?history=yes
http://.../trac/wiki/WikiPage?version=1&diff=yes
Attachments
Change History
Note: See
TracTickets for help on using
tickets.


