If I remember well, a user can overwrite the previous release of a topic by adding a proper
cmd=xxx option in the save url.
By repeating the process he/she can remove all the version of a topic.
I suggest to have two different save scripts
- saveadmin for usage only by a poweruser (htaccess protected)
- save (without the option) for normal usage
--
AndreaSterbini - 13 Sep 2000
I propose to secure this when we have
AuthenticationBasedOnGroups in place.
--
PeterThoeny - 13 Sep 2000
The 01 Dec 2000 production release protects the
cmd=xxx option. Only members of the
TWikiAdminGroup can issue this command.
--
PeterThoeny - 26 Nov 2000