Please give access control to this field, not based on roles but on node author/ownership. As it stands now, even if the link on the referenceable node is not displaying, any smart user can add content to another user's account from the URL.

Comments

Triumphent’s picture

Issue summary: View changes

Edit

Triumphent’s picture

Issue summary: View changes

Edit #2

Triumphent’s picture

Priority: Normal » Critical
Alex Andrascu’s picture

Assigned: Unassigned » Alex Andrascu
Alex Andrascu’s picture

Issue summary: View changes

Edit #3