redmine_private_wiki
redmine_private_wiki copied to clipboard
User can access content of private wiki via full-text search
I create a private wiki for developers group with this content "password AD89798qw" I login with a developer account As a developer I clic on forbidden wiki and as expected redmine cannot see anything As a developer I perform search with this keywork "password" Redmine show me the title of private page and the following content result "password AD89798qw"
Regards
Uh, thats really bad! Please fix!
+1 for fixing it.