Expected Space permissions (for example VIEWSPACE for a group) are migrated to XWiki.XWikiGlobalRights objects on the WebPreferences page of each space. Actual Not a single space permission is migrated, and nothing is logged — no warning, no error. The backup contains 5,038 SpacePermission objects across 41 spaces; after the import there is no XWikiGlobalRights object on any space-level WebPreferences. Spaces that were restricted to individual groups in Confluence are readable by every logged-in user in XWiki. Cause In this backup format, SpacePermission references its space through <property name="spaceId">…</property>. ConfluenceXMLPackage#readSpacePermissionObject reads properties.getLong(KEY_PAGE_SPACE, null) with KEY_PAGE_SPACE = "space", receives null and skips the record:
Long permissionId = asLong(r.readRecord(properties));
Long spaceId = properties.getLong(KEY_PAGE_SPACE, null);
if (permissionId != null && spaceId != null
&& !shouldIgnoreSpace(spaceId) && properties.getBoolean(KEY_ACTIVE, true)
) {
saveSpacePermissionProperties(properties, spaceId, permissionId);
}
ConfluenceXMLStreamReader stores property names verbatim, so spaceId is never mapped to space. Still the same on master as of 2026-09-28. Second consequence: home page restrictions are lost as well ConfluenceInputFilterStream#sendSpaceRights returns early when the space permission list is empty. The loop that sends the home page's inherited rights comes after that return:
Collection<Object> spacePermissions = spaceProperties.getList(ConfluenceXMLPackage.KEY_SPACE_PERMISSIONS);
if (spacePermissions.isEmpty()) {
return;
}
…
if (inheritedRights != null) {
for (ConfluenceRight confluenceRight : inheritedRights) {
sendInheritedPageRight(homePageProperties, proxyFilter, confluenceRight);
}
}
In our import this affected 18 space home pages whose view restrictions were dropped. Because Confluence inherits page restrictions downwards, this exposes the whole page tree below those home pages.{} Suggested fix
- Fall back to spaceId when space is absent.
- Send the home page's inherited rights independently of whether the space permission list is empty.
Sample record fromentities.xml{{}}
<object class="SpacePermission" package="com.atlassian.confluence.security">
<id name="id">4174308</id>
<property name="spaceId">4161554</property>
<property name="type">EDITBLOG</property>
<property name="group" />
<property name="userSubject" class="ConfluenceUserImpl" package="com.atlassian.confluence.user"><id name="key">…</id></property>
<property name="allUsersSubject" />
<property name="active">true</property>
</object>
{}{}How it was verified
| Observation |
Source |
| 5,038 SpacePermission objects with a spaceId property and no space property; Space objects have no permissions collection |
entities.xml of the backup |
| The filter reads space |
ConfluenceXMLPackage.java, tag confluence-9.96.3 and master |
| Property names are stored verbatim |
ConfluenceXMLStreamReader.java |
| 0 space-level rights in the wiki after the import, while 254 page-level view restrictions were migrated correctly |
database query |
| 18 space home pages without the view restriction they had in Confluence |
own verification script |
|