When editing an unpublished node with an expired token and then clicking on "renew" I get presented with a list of tokens from other nodes.
This is not a security issue, the user is allowed to see those nodes, but an inconvenience, as the list can be very long.
See screenshot.
| Comment | File | Size | Author |
|---|---|---|---|
| #2 | 3129220.patch | 634 bytes | chr.fritsch |
| Bildschirmfoto vom 2020-04-20 10-58-45.png | 57.83 KB | killes@www.drop.org |
Comments
Comment #2
chr.fritschI could reproduce it. The attached patch fixes it
Comment #4
chr.fritschDone