Permissions not or only improperly checked in some contexts #19

오픈
" crtxcr2020-09-21 22:08:26 +02:00을 오픈" · 0개의 코멘트
소유자
  1. When a user has no permission to see the page history, he still knows about older entries from the global history pages, which can be a metadata leak. They should not be there

  2. Search must also consider permissions such as can_read etc.

1. When a user has no permission to see the page history, he still knows about older entries from the global history pages, which can be a metadata leak. They should not be there 2. Search must also consider permissions such as can_read etc.
crtxcr added the
bug
enhancement
labels 2020-09-21 22:08:26 +02:00
crtxcr changed title from Permissions not or improperly checked in some contexts to Permissions not or only improperly checked in some contexts 2020-09-21 22:08:37 +02:00
"로그인하여 이 대화에 참여"
마일스톤 없음
담당자 없음
참여자 1명
알림
마감일
기한이 올바르지 않거나 범위를 벗어났습니다. 'yyyy-mm-dd'형식을 사용해주십시오.

마감일이 설정되지 않았습니다.

의존성

No dependencies set.

Reference: crtxcr/qswiki#19
No description provided.