[xwiki-users] Having the "edit" right, the user has the right to change access rights
When a user has editing right, and when enabling the Advanced user type, this user can change the access rights of the page. Was it meant to be like that? I recall that this option (in previous versions) was only available for users who have admin rights, not for anyone. Version 2.2.1.27354 and the one that is on playground, 2.3.28624, present this issue. -- Atenciosamente, Erica Usui.
Yes. Permissions are just objects in the page, if you are allowed to modify the page then you are allowed to modify it's objects. This makes logical sense because the worst you can do by modifying the permissions on a page is to allow everyone to modify the page which you could have done anyway by giving them your password. Nobody has the power to deny adminstrators access to the page, the admin permission on the space or wiki level trumps denial of permissions on the page level. Erica Usui wrote:
When a user has editing right, and when enabling the Advanced user type, this user can change the access rights of the page. Was it meant to be like that?
I recall that this option (in previous versions) was only available for users who have admin rights, not for anyone. Version 2.2.1.27354 and the one that is on playground, 2.3.28624, present this issue.
participants (2)
-
Caleb James DeLisle -
Erica Usui