Project

General

Profile

Actions

Defect #31778

closed

Total estimated time issue query column and issue field might leak information

Added by Felix Schäfer over 5 years ago. Updated about 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Issues
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Resolution:
Affected version:

Description

The total estimated time information will show the sum of the estimated times of the issues and its subissues. This calculation does not verify if the current user is allowed to see the sub issues though, which might lead to an information leak.

Attached is a patch with a test for this issue. This patch was created and contributed by Gregor Schmidt.


Files


Related issues

Related to Redmine - Defect #32022: IssueSubtaskingTest fails with high probabilityClosedGo MAEDA

Actions
Actions #1

Updated by Go MAEDA over 5 years ago

  • Target version set to 4.0.5

Setting the target version to 4.0.5.

Actions #2

Updated by Go MAEDA about 5 years ago

  • Status changed from New to Resolved
  • Assignee set to Go MAEDA

Committed the fix. Thank you.

Actions #3

Updated by Go MAEDA about 5 years ago

  • Status changed from Resolved to Closed
  • Target version changed from 4.0.5 to 3.4.12
Actions #4

Updated by Go MAEDA about 5 years ago

  • Related to Defect #32022: IssueSubtaskingTest fails with high probability added
Actions

Also available in: Atom PDF