Problem/Motivation
Administer the Remove HTTP headers settings has security implications and that granting it should be done with care.
Proposed resolution
Add restrict access: TRUE to permission.
Remaining tasks
Create patchReview/RTBCCommit
User interface changes
Provides message "Warning: Give to trusted roles only; this permission has security implications." for Administer the Remove HTTP headers settings permission.
API changes
None.
Data model changes
None.
| Comment | File | Size | Author |
|---|---|---|---|
| #2 | remove_http_headers-restrict_access-3057423-2.patch | 336 bytes | i-trokhanenko |
Comments
Comment #2
i-trokhanenkoPlease review!
Comment #3
i-trokhanenkoComment #4
Roman Dyn commentedPatch #2 works well for me. Please commit.
Comment #5
Roman Dyn commentedComment #7
orlando.thoenyThanks :) Commtted
Comment #8
orlando.thoeny