Permissions not or only improperly checked in some contexts #19

Avoinna
2020-09-21 22:08:26 +02:00 avasi crtxcr · 0 kommenttia
Omistaja
  1. When a user has no permission to see the page history, he still knows about older entries from the global history pages, which can be a metadata leak. They should not be there

  2. Search must also consider permissions such as can_read etc.

1. When a user has no permission to see the page history, he still knows about older entries from the global history pages, which can be a metadata leak. They should not be there 2. Search must also consider permissions such as can_read etc.
crtxcr added the
bug
enhancement
labels 2020-09-21 22:08:26 +02:00
crtxcr muutti otsikon Permissions not or improperly checked in some contexts otsikoksi Permissions not or only improperly checked in some contexts 2020-09-21 22:08:37 +02:00
Sign in to join this conversation.
Ei merkkipaalua
Ei käsittelijää
1 osallistujaa
Ilmoitukset
Määräpäivä
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

Määräpäivää ei asetettu.

Riippuvuudet

Riippuvuuksia ei asetettu.

Reference: crtxcr/qswiki#19
No description provided.