Permissions not or only improperly checked in some contexts #19

Open
2020-09-21 22:08:26 +02:00 geopend door crtxcr · 0 opmerkingen
Eigenaar
  1. When a user has no permission to see the page history, he still knows about older entries from the global history pages, which can be a metadata leak. They should not be there

  2. Search must also consider permissions such as can_read etc.

1. When a user has no permission to see the page history, he still knows about older entries from the global history pages, which can be a metadata leak. They should not be there 2. Search must also consider permissions such as can_read etc.
crtxcr voegde de
bug
enhancement
labels 2020-09-21 22:08:26 +02:00 toe
crtxcr titel aangepast van Permissions not or improperly checked in some contexts naar Permissions not or only improperly checked in some contexts 2020-09-21 22:08:37 +02:00
Log in om deel te nemen aan deze discussie.
Geen mijlpaal
Niet toegewezen
1 deelnemers
Notificaties
Vervaldatum
De deadline is ongeldig of buiten bereik. Gebruik het formaat 'jjjj-mm-dd'.

Geen vervaldatum ingesteld.

Afhankelijkheden

Geen afhankelijkheden ingesteld.

Referentie: crtxcr/qswiki#19
No description provided.