Permissions not or only improperly checked in some contexts #19

Aperto
aperto 2020-09-21 22:08:26 +02:00 da crtxcr · 0 commenti
Proprietario
  1. When a user has no permission to see the page history, he still knows about older entries from the global history pages, which can be a metadata leak. They should not be there

  2. Search must also consider permissions such as can_read etc.

1. When a user has no permission to see the page history, he still knows about older entries from the global history pages, which can be a metadata leak. They should not be there 2. Search must also consider permissions such as can_read etc.
crtxcr ha aggiunto le
bug
enhancement
etichette 2020-09-21 22:08:26 +02:00
crtxcr Titolo modificato da Permissions not or improperly checked in some contexts a Permissions not or only improperly checked in some contexts 2020-09-21 22:08:37 +02:00
Effettua l'accesso per partecipare alla conversazione.
Nessuna milestone
Nessuna assegnatario
1 Partecipanti
Notifiche
Data di scadenza
La data di scadenza non è valida o fuori intervallo. Si prega di utilizzare il formato 'aaaa-mm-dd'.

Nessuna data di scadenza impostata.

Dipendenze

Nessuna dipendenza impostata.

Riferimento: crtxcr/qswiki#19
No description provided.