jspwiki-user mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Geoff O'Callaghan" <geoffocallag...@gmail.com>
Subject Re: authenticated and search
Date Sun, 09 Mar 2008 23:31:10 GMT
On Sunday 09 March 2008 04:50:09 Janne Jalkanen wrote:
> > Mostly, it confuses people as they may have had their session time
> > out, do a
> > search and get no results on a normal looking search results page.
> >
> > Is there something I should be configuring better??  Or is it a bug?
>
> It appears to be a bug.  For some reason, to access Search.jsp you
> don't need any permissions - all that is checked is a generic
> permission to read "os.name" system property.
>
> Andrew?  I think this should be filed as a security bug.  I also fear
> that the DummyPermission is used elsewhere as well.  In the very
> least, we should check for something generic, like view permission to
> the front page.

Do I need to do anything to file this as a bug or have you already taken care 
of it :-)

Cheers
Geoff

Mime
View raw message