Uploaded image for project: 'SR for Confluence - Development'
  1. SR for Confluence - Development
  2. SRCONF-776

Make sure all Confluence features with a code editor abide by script edit permissions

    Details

    • Type: Bug
    • Status: Done (View Workflow)
    • Priority: High
    • Resolution: Done
    • Affects Version/s: 5.5.9
    • Fix Version/s: 5.6.0, 5.6.4, 5.6.5
    • Component/s: None
    • Labels:
      None
    • Sprint:
      SR Squad 116, SR Squad 117, SR Squad 118, SR Squad 119, SR Squad 120, SR Squad 121
    • Story Points:
      2
    • Critical Points:
      0

      Description

      Known missed spots at the moment:

      • Script Jobs (this is also cross product), code editor is available even when the user has no permissions. The REST resource also does not validate permissions when creating/updating a job, which allows an unauthorised user to create jobs with code via REST.

        Attachments

          Structure

            Activity

              People

              Assignee:
              rholban Roland Holban [X] (Inactive)
              Reporter:
              rholban Roland Holban [X] (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:

                  Structure Helper Panel