Permissions not or only improperly checked in some contexts #19

Öppen
öppnade 2020-09-21 22:08:26 +02:00 av crtxcr · 0 kommentarer
Ägare
  1. When a user has no permission to see the page history, he still knows about older entries from the global history pages, which can be a metadata leak. They should not be there

  2. Search must also consider permissions such as can_read etc.

1. When a user has no permission to see the page history, he still knows about older entries from the global history pages, which can be a metadata leak. They should not be there 2. Search must also consider permissions such as can_read etc.
crtxcr added the
bug
enhancement
labels 2020-09-21 22:08:26 +02:00
crtxcr ändrade titeln från Permissions not or improperly checked in some contexts till Permissions not or only improperly checked in some contexts 2020-09-21 22:08:37 +02:00
crtxcr refererade till detta ärende från en incheckning 2021-10-26 23:08:35 +02:00
Logga in för att delta i denna konversation.
Ingen Milsten
Ingen tilldelad
1 Deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet 'åååå-mm-dd'.

Inget förfallodatum satt.

Beroenden

No dependencies set.

Reference: crtxcr/qswiki#19
No description provided.