Project

General

Profile

Actions

Refactor #3930

closed

editing_self permission check is 'global'

Added by Ohad Levy over 10 years ago. Updated almost 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Authentication
Target version:
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

While this does not seems like a bug, the code in the permission checking system always validates if the user edit it self (so a non admin user can edit his account), but this code is checked globally for all permissions checks.

also, the normalization of controllers names is spread across the app.


Related issues 1 (0 open1 closed)

Blocks Foreman - Bug #3858: No menus shown for non-admin usersClosed12/11/2013Actions
Actions #1

Updated by Ohad Levy over 10 years ago

  • Blocks Bug #3858: No menus shown for non-admin users added
Actions #2

Updated by Ohad Levy over 10 years ago

  • Status changed from New to Ready For Testing
Actions #3

Updated by Ohad Levy over 10 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100
Actions #4

Updated by Dominic Cleal over 10 years ago

  • translation missing: en.field_release set to 2
Actions

Also available in: Atom PDF