exist icon indicating copy to clipboard operation
exist copied to clipboard

child collection permissions affect parent

Open telic opened this issue 10 years ago • 2 comments

Removing the execute permission on a collection prevents unauthenticated access to the parent through REST.

telic avatar Jul 16 '15 21:07 telic

eXist version?

Can you provide a simple reproducible test?

joewiz avatar Jul 16 '15 22:07 joewiz

I've had this problem in 2.0, 2.1, 2.2, and now 3.0rc1.

Simply setting the 'apps' collection's permissions to "crwxrwxr--" prevents unauthenticated access over REST to the entire database.

telic avatar Jul 16 '15 22:07 telic