incubator-jspwiki-user mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Janne Jalkanen <Janne.Jalka...@ecyrd.com>
Subject Re: authenticated and search
Date Sat, 08 Mar 2008 17:50:09 GMT
> Mostly, it confuses people as they may have had their session time  
> out, do a
> search and get no results on a normal looking search results page.
>
> Is there something I should be configuring better??  Or is it a bug?

It appears to be a bug.  For some reason, to access Search.jsp you  
don't need any permissions - all that is checked is a generic  
permission to read "os.name" system property.

Andrew?  I think this should be filed as a security bug.  I also fear  
that the DummyPermission is used elsewhere as well.  In the very  
least, we should check for something generic, like view permission to  
the front page.

/Janne

Mime
View raw message