Closed (duplicate)
Project:
Drupal core
Version:
7.x-dev
Component:
comment.module
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
28 Apr 2006 at 17:45 UTC
Updated:
14 Oct 2010 at 09:13 UTC
If you have 'administer comments' privilege, try comment/edit/xx or comment/delete/xx, where xx is a non-existent comment. hm...
The attached patch tries to fix this.
| Comment | File | Size | Author |
|---|---|---|---|
| comment.module.edit_del_nfnd.patch.txt | 2.22 KB | markus_petrux |
Comments
Comment #1
dries commentedI think it is better to fix this inside comment_edit() et al. We already perform access checks in those functions and therefore might be able to save a database query. Could you explore that path? Thanks.
Comment #2
ricabrantes commentedThis bug is active in d5 and d6, Moving to new version..
Comment #3
gpk commentedJust hit this in 6.14...
Comment #4
sivaji_ganesh_jojodae commentedThis is a duplicate of #329023: comment.module should check for valid commend id on comment/edit/* and the issue reported here is already fixed for D7.