On 18 Aug 2016, at 13:53, Stefan Taferner
<taf(a)porscheinformatik.at> wrote:
Hi all,
The day after upgrading
http://selfbus.myxwiki.org to 8.2.1, I found a handful of spammer
accounts that were created as local users in the wiki.
The wiki was configured to
* Only an admin can send invitations to join this wiki
* Both global and local users are available in the wiki
Interestingly this still allows new users to be registered.
Also strange is that the registration captcha does not show as it should also.
The wiki is now set to allow only global users, so there is no immediate problem.
I only wanted to report my observations, as it looks like a bug in xwiki to me.
Whether someone can create an account depends on the “register” permission for guest. This
is what you need to configure for your wiki.
Global/Local user simply defines where the user accounts can be created (on the main wiki
- ie global -, or on the local wiki - ie local).
On the main wiki we allow everyone to register accounts :)
Thanks
-Vincent