Closed (fixed)
Project:
Entity Registration
Version:
7.x-1.x-dev
Component:
Registration Core
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
26 Jun 2012 at 19:17 UTC
Updated:
27 Jun 2014 at 21:08 UTC
Jump to comment: Most recent
Comments
Comment #1
ezra-g commentedMarking as "needs review".
Comment #2
levelos commentedCommitted, thanks guys.
Comment #4
mrfelton commentedI think this probably should have been marked as a security release, as it has security implications.
Comment #5
gregglesI could go either way on whether it needs a "security update" tag on the release node. It only allowed admins with "Administer registration states" permission to inject xss - that permission is marked as "restrict access" => TRUE so it gives a big warning in the permissions page saying it should only be granted to highly trusted people. On top of that this is a beta module, so there is an implied state of "each new release will contain critical bugfixes and people should update fast."
@levelos - if you want the security update tag please comment here and I can do it for you (only users with certain d.o permissions can do it).
Comment #6
levelos commentedI appreciate the consideration and am happy to have the tag added if it would benefit the community. I'm personally ambivalent, although seems like water under the bridge at this point ....
Comment #7
gregglesThere's ~400 users who are using an old version. Adding the security update tag would give them a red warning encouraging them to update.
As I write this I'm remembering that when an admin permission (i.e. with restrict access) is a mitigating factor that we typically discourage the use of the security update tag so we don't create unnecessary "noise" for site admins. So...yeah, I'm now opposed to the idea of adding the tag.