On 1 Oct 2015 at 08:51:01, vincent(a)massol.net
(vincent@massol.net(mailto:vincent@massol.net)) wrote:
I’m ok on
my side to allow Owner to be able to use the “Always on
this wiki” visibility for JSX/SSX.
Allowing PR is another matter and
I’m -1 for that, it’s too dangerous. With PR you can do
anything: hack the OS, delete all the wikis of the farm, etc
(voluntarily or not!).
Yes I'm agree with you. It's too dangerous for groovy code and JAR...
But are there same risk if you allow only full velocity code+xwiki API?
(I don't know if some methods need PR anyway)