Defect #4691

Permission on "my page"

Added by Luca Minuti almost 8 years ago. Updated almost 8 years ago.

Status:ClosedStart date:2010-01-29
Priority:NormalDue date:
Assignee:-% Done:

0%

Category:Permissions and roles
Target version:0.9.2
Resolution:Fixed Affected version:0.9.1

Description

If I add the calendar to "my page" I can see the issues also if my role doesn't allow it (role: issue tacking/view issue).

Redmine 0.8.7.devel.3092 (MySQL)

Associated revisions

Revision 3351
Added by Jean-Philippe Lang almost 8 years ago

Fixed: potential security leak on my page calendar (#4691).

History

#1 Updated by Jean-Philippe Lang almost 8 years ago

  • Status changed from New to Closed
  • Target version set to 0.9.2
  • Affected version (unused) changed from 0.8.7 to 0.9.1
  • Resolution set to Fixed
  • Affected version changed from 0.8.7 to 0.9.1

Fixed in r3351.

Also available in: Atom PDF