Test Case: TC.ACL.2.4.103.1

Pre test: Set up ACL user that does not have an Admin role in container or application. For this test, we did not configure container managed security.

ACL Testing steps

  1. Logged into http://www.helpingstudents.org/JSPWiki/Login.jsp
  2. Test page http://www.helpingstudents.org/JSPWiki/Wiki.jsp?page=MMisovec

Test results: TC.ACL.2.4.103.1 Result - ACL did not restrict editing for user that was not listed in ACL.

Following the test we re-installed version 2.4.56 with container managed and jspwiki policy security (Container roles and ACLs). Our previous 2.4.56 configuration may have been a factor.

Our configuration may have contributed. Will attach jspwiki.policy, Server.xml, web.xml, and other files used during test upon request.

Add new attachment

In order to upload a new attachment to this page, please use the following box to find the file, then click on “Upload”.
« This page (revision-9) was last changed on 24-Jul-2007 16:22 by M Misovec [RSS]