This is not a security issue, rather an UI or usability related issue.

1) Queues, a user is not allowed to modify, should not be displayed in the admin queue listing.
2) If a queue has no user roles assigned, access to a queue should be denied (spits out a PHP warning instead currently).

Attached patch fixes both issues.

CommentFileSizeAuthor
nodequeue-DRUPAL-5--2.access.patch2.39 KBsun

Comments

ezra-g’s picture

Status: Needs review » Closed (duplicate)

These issues are now addressed by the latest patch at #272298: Modular Access control for queue, subqueue viewing and manipulation. Thanks for reporting them!