It is not undocumented. It is documented in the same place as all other security documentation. My guess is that this is a conceptual difference in how people think about ACLs.

http://doc.jspwiki.org/2.4/wiki/Security

"By default, wiki pages do not have access control lists. When a page doesn't have an ACL, the default security policy for the page applies."

/Janne

On 11 Jan 2008, at 22:58, Florian Holeczek wrote:

maybe add a
[{ALLOW view anonymous}] - to allow anonymous (I think then everyone to view)
[{ALLOW edit florian}]
Florian wrote this...

Yes, that's fine (with Anonymous, case sensitive). I already knew this
before, though :-)

Maybe it's an "undocumented feature" that once a policy rule is given, the
default policy rules are deactivated completely?

Regards,
 Florian

Reply via email to