Replicate:
- Create two docs: Main and Secondary
- Sync a page from the Main doc to the Secondary doc
- Grant a user Edit access to only the Secondary doc
- Have that user open any page in the Secondary doc (not the synced page)
The Issue:
Even though the user (MS) does not have access to the Main doc and is not on the synced page, they still appear as an active user in the Main doc (see the screenshot above).
This is a serious privacy concern since it exposes the presence of users in a document they should not have access to.