xwikisas / application-forum

Forum Application (Pro)
GNU Lesser General Public License v3.0
0 stars 5 forks source link

Simple users can see the Edit button on other's users Forums, Topics, Answers and Comments #88

Open ane-gabriela opened 4 years ago

ane-gabriela commented 4 years ago

Steps to reproduce:

  1. As Admin or a simple user eg. user01 create a Forum, Topic, Answer, Comment
  2. As another simple user eg. user02 access the Forums home page
  3. Click on Edit next to the Forum
  4. Access the Topic
  5. Click on Edit
  6. Access an Answer
  7. Click on Edit Answer
  8. Observe the Comment
  9. Click on Edit

Expected results: A simple user shouldn't be able to edit Forum/Topic/Answer/Comments that aren't his or he is not the Forum/Topic creator.

Actual results:

Environment: Windows 10, XWiki 12.1 with MySQL 5.7 and IE 11, Forum Application (Pro) 2.7.1

ForumEdit

User2View

ane-gabriela commented 1 year ago

When simple users click on Edit next to a comment of another user/admin

Failed

Environment: Windows 11, XWiki 14.10.18 with Forum Application (Pro) 2.9, Chrome 118

ndascalita commented 10 months ago

Could reproduce in XWiki 14.10.20 with Forum Application Pro 2.9.1