Closed (fixed)
Project:
Drupal.org security advisory coverage applications
Component:
module
Priority:
Major
Category:
Task
Assigned:
Issue tags:
Reporter:
Created:
28 Aug 2020 at 13:17 UTC
Updated:
6 Mar 2021 at 12:19 UTC
Jump to comment: Most recent
Comments
Comment #2
arshadkhan35 commentedComment #3
arshadkhan35 commentedComment #4
arshadkhan35 commentedComment #5
vigneshvalliappan commentedHi @arshadkhan35,
Please implement hook_help, and I see that the settings form has "access content" permission which means that it can be accessed by anonymous user as well, So please use your own permissions.
Comment #6
avpadernoShowing the output given from a tool isn't making a manual review. I removed those review from the Manual reviews list.
Comment #7
avpadernoYes, the access content permission isn't thought to be used for the settings pages a module uses. In a site, that permission could be given to anonymous users too, as vigneshvalliappan said, and it's pretty normal to do so. Using that permission for other purposes is a security issue, IMO.
Comment #8
arshadkhan35 commentedThanks @vigneshvalliappan , @kiamlaluno the permission issue is resolved and Hook_help is implemented now, Thanks @kiamlaluno for clearing my understanding of manual review.
Comment #9
arshadkhan35 commentedComment #10
arshadkhan35 commentedComment #11
arshadkhan35 commentedComment #12
arshadkhan35 commentedComment #13
matroskeenHello there,
I've reviewed the application and created several tasks in project issues queue:
I don't consider them as bugs or security issues, that's why I'm not moving this task to "Needs Work".
Comment #14
avpadernoComment #15
arshadkhan35 commentedThanks @Matroskeen for review, all the task created above have been incorporated. Thanks for the patch.
Comment #16
arshadkhan35 commentedI am changing priority as per https://www.drupal.org/node/539608
Comment #17
avpadernoI edited the issue tags as per https://www.drupal.org/node/1975228.
Comment #18
avpadernoComment #19
avpadernoThank you for your contribution! I am going to update your account.
These are some recommended readings to help with excellent maintainership:
You can find more contributors chatting on the IRC #drupal-contribute channel. So, come hang out and stay involved.
Thank you, also, for your patience with the review process.
Anyone is welcome to participate in the review process. Please consider reviewing other projects that are pending review. I encourage you to learn more about that process and join the group of reviewers.
I thank all the dedicated reviewers as well.
Comment #20
avpaderno