Active
Project:
Node Authorize Link
Version:
2.x-dev
Component:
Code
Priority:
Normal
Category:
Feature request
Assigned:
Unassigned
Reporter:
Created:
1 Jul 2011 at 00:38 UTC
Updated:
11 Aug 2023 at 16:11 UTC
Jump to comment: Most recent
Comments
Comment #1
dave reidSince this module has a full release, this now has to be reported to the security team.
Comment #2
coltraneSecurity Team has deemed this issue is okay to be handled publicly.
Comment #3
tunicThis is a very old report. Currently, the module allows to select with operations are enabled for a content type, so admins can enable view but no delete. Not perfect but at least allows to expose content without the risk of being deleted.
However, would be interesting to have this. Patches ar welcome.