Reported against:
dokuwiki-rc2006-10-19
Steps to reproduce:
* logon to some dokuwiki
* open some page for edit
* copy&paste the following text fragment at the beginning of the page
http://lksjfdlkjd?p=ksdfkjds&u=asdasd
* wait until background save is triggered (make some additional modifications)
* try to save the page - you will get "Permission denied" because you are not logged any more
Explanation:
* page text is not escaped correctly during background save, POST variables look like this
call=lock&id=start&prefix=&wikitext=http://lksjfdlkjd?p=ksdfkjds&u=asdasd...
Recomended fix:
* review all js code and use correct escape function (encodeURIComonent ??)