Closed (fixed)
Project:
Jobtrack
Version:
6.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Feature request
Assigned:
Unassigned
Reporter:
Created:
16 Mar 2009 at 04:58 UTC
Updated:
14 Apr 2009 at 01:30 UTC
This is a security problem: although anonymous users have no read access to jobtickets nodes, they still can search through its entire contents!
Comments
Comment #1
jeremy commentedMarking as a feature request: integrate Jobtrack with search to check permissions and only allow users to be able to search tickets that they can access. It has been on my internal TODO list for a while, moving here now to track until it happens.
Patches are welcome.
Comment #2
jeremy commentedFeature committed.
Comment #3
roball commentedExcellent! Thank you - now working fine :-)