Just enabled the module to do some testings and I found that the default views exported by this module, which serve as great examples, are enabled by default. I think they should be disabled, otherwise, unaware users that install this module may leave the views accessible by everyone (as set on your defaults). For instance, anon users may see a list of orders by just going at /orders.

Comments

madsph’s picture

Yes you are right - this has been fixed in the 6.x.3.x-dev version (see #475504: Views should be disabled by default for more info)

hanoii’s picture

Why not backport that to 2.x? Need a patch?

madsph’s picture

I don't think that this is serious enough to make a new release. I do not want to bother people already having a site running with having to deal with making an upgrade - unless it is really needed. Even though it is simple and straight forward, the admins must still take the time to go over the release, update the test-site, go over their test and finally put it into production.

I do however plan to make the 3.x-dev the new official release since it seems pretty stable, and contains a lot of bug fixes. I just want to be sure that I have enough time on my hand to handle any support requests in the days right after doing so.

Your request has made me aware, that this may be more urgent than i thought - so thank you for reporting. Feedback is always VERY welcome.

The correction has already been made in the 2.x and 3.x-dev branches.

hanoii’s picture

Status: Active » Fixed

I guess we can considered this issue fixed and maybe focus on releasing a new stable version of the 3.x branch?

a.=

madsph’s picture

Status: Fixed » Closed (fixed)

This is taken care of by the 3.0 release