the access callback for /certify is simply TRUE
this caused anonymous users to get to view "their certificates" as well..

made most sense to use "View my certificates", so i changed it, but not quite sure if that was the intended permission

CommentFileSizeAuthor
0001-missing-proper-permission.patch938 bytesAnonymous (not verified)

Comments

fuzzy76’s picture

Thanks for reporting this, it will be part of the next update :) The /certify screen has never been considered finished, which is why it isn't linked to from anywhere. Your patch definitely helps.

fuzzy76’s picture

Assigned: Unassigned » fuzzy76
Status: Needs review » Fixed

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.