Permissions not or only improperly checked in some contexts #19

开启中
crtxcr2020-09-21 22:08:26 +02:00创建 · 0 评论
所有者
  1. When a user has no permission to see the page history, he still knows about older entries from the global history pages, which can be a metadata leak. They should not be there

  2. Search must also consider permissions such as can_read etc.

1. When a user has no permission to see the page history, he still knows about older entries from the global history pages, which can be a metadata leak. They should not be there 2. Search must also consider permissions such as can_read etc.
crtxcr2020-09-21 22:08:26 +02:00 添加标签 bugenhancement
crtxcr2020-09-21 22:08:37 +02:00 修改标题 Permissions not or improperly checked in some contextsPermissions not or only improperly checked in some contexts
登录 并参与到对话中。
1 名参与者
通知
截止日期
未设置截止日期。
依赖工单

未设置依赖工单。

引用:crtxcr/qswiki#19