Skip to content

Unauthorized disclosure of wiki pages in search

Summary

Wiki page appear in search results even though wiki permission is set to Only team members.

Steps to reproduce

What is the current bug behavior?

Show the content of wiki pages that matches the searched query.

Though opening the wiki pages directly result in: Access denied.

What is the expected correct behavior?

Not to show wiki pages.

Relevant logs and/or screenshots

Project settings:

Screen_Shot_2017-04-19_at_6.28.16_PM

Result page:

Screen_Shot_2017-04-19_at_6.27.33_PM

Same issue when the project visibility is internal and a user outside the project group search.