There are 3 updates, 2 comments.
 
 
XWiki Platform / cid:jira-generated-image-avatar-1bbdbda3-56bd-424b-92b1-22f9b8d59a75 XWIKI-20498 Open

Prevent users with no script right to add Gadgets with velocity code or add a warning when they try to add one

 
View issue   ยท   Add comment
 

3 updates

 
cid:jira-generated-image-avatar-501a04e9-05c1-4077-84eb-f00a0a956e06 Changes by Nikita Petrenko on 12/Sep/25 11:53
 
Attachment: warning from required rights on edit attempt.jpeg
Attachment: required rights for Dashboard page.jpeg
Attachment: result of editing by user without script or PR rights.jpeg
 
 

2 comments

 
cid:jira-generated-image-avatar-501a04e9-05c1-4077-84eb-f00a0a956e06 Nikita Petrenko on 12/Sep/25 11:52
 
Is it relevant? Since [XWiki 15.9|https://www.xwiki.org/xwiki/bin/view/ReleaseNotes/Data/XWiki/15.9#HRequiredRights] and [XWiki 17.4-RC.|https://www.xwiki.org/xwiki/bin/view/ReleaseNotes/Data/XWiki/17.4.0RC1/#HNewUIforsettingrequiredrights] user will see warning concerning lacks of rights. Duplicated by [ XWIKI-21311 |https://jira . xwiki

Updating my comment, with result in XWiki 17
. org/browse/XWIKI 7 - 21311] RC after I activate the required right with _recommend_ option by admin account, and attempt to start editing Dashboard home page with normal user that lacks Script and PR rights - I'm getting warning. 

After saving this page with normal user I'm not ending with velocity errors, but translations are missed, and user see translations key calls.
 
cid:jira-generated-image-avatar-501a04e9-05c1-4077-84eb-f00a0a956e06 Nikita Petrenko on 12/Sep/25 11:54
 
Is it relevant? Since [XWiki 15.9|https://www.xwiki.org/xwiki/bin/view/ReleaseNotes/Data/XWiki/15.9#HRequiredRights] and [XWiki 17.4-RC.|https://www.xwiki.org/xwiki/bin/view/ReleaseNotes/Data/XWiki/17.4.0RC1/#HNewUIforsettingrequiredrights] user will see warning concerning lacks of rights. Duplicated by XWIKI-21311.

Updating my comment, with result in XWiki 17.7-RC after I activate the required right with _recommend_ option by admin account
[^required rights for Dashboard page.jpeg] , and attempt to start editing Dashboard home page with normal user that lacks Script and PR rights - I'm getting warning [^warning from required rights on edit attempt . jpeg].  

After saving this page with normal user I'm not ending with velocity errors, but translations are missed, and user see translations key calls.
[^result of editing by user without script or PR rights.jpeg].