Test Case: TC.ACL.2.4.103.1
Pre test: Set up ACL user that does not have an Admin role in container or application. For this test, we did not configure container managed security.
ACL Testing steps
- Logged into http://www.helpingstudents.org/JSPWiki/Login.jsp
- Test page http://www.helpingstudents.org/JSPWiki/Wiki.jsp?page=MMisovec
Test results: TC.ACL.2.4.103.1 Result - ACL did not restrict editing for user that was not listed in ACL.
Following the test we re-installed version 2.4.56 with container managed and jspwiki policy security (Container roles and ACLs). Our previous 2.4.56 configuration may have been a factor.
Our configuration may have contributed. Will attach jspwiki.policy, Server.xml, web.xml, and other files used during test upon request.