For those of you using the SQL plugin, I have a question.
I know that I can use the Macro Security plugin to restrict who can use a plugin (and that is good). But, aside from that.
Lets say that I have a user who is allowed to use the SQL plugin, and that I have two spaces. One space called "Open" and one space called "Super secret". The user who has permission to use the plugin, and access to the "Open" space, but not to the "Super secret" space, will he be able to do a sql query from his "Open" space, to gain access to the "Super secret" space and display the information on his "Open" space?
Yes, once you provide the user access to a datasource representing the Confluence database, then you are providing access to all the data - Confluence security is not involved. This is strictly a database access thing just like given the user an external query tool to look at the database.
In this situation, you want to restrict direct access to the SQL macro by the user and instead provide query capabilities using techniques like Live-template support or administrator provided pages that can be included in the user's pages. These techniques mean that the administrator or trusted user controls the query.
Thanks Bob, I was afraid that you were going to say that. I'll investigate your suggestion.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.