[Tickets #1880] NEW: AttachedFile.php should respect permissions
bugs@bugs.horde.org
bugs at bugs.horde.org
Thu Apr 28 02:36:09 PDT 2005
DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.
Ticket URL: http://bugs.horde.org/ticket/?id=1880
-----------------------------------------------------------------------
Ticket | 1880
Created By | tasin at fhm.edu
Summary | AttachedFile.php should respect permissions
Queue | Wicked
State | Unconfirmed
Priority | 2. Medium
Type | Bug
Owners |
+New Attachment | wicked1.diff
-----------------------------------------------------------------------
tasin at fhm.edu (2005-04-28 02:36) wrote:
Like Bug #915 only for attaching files.
Actually it is possible to attach files to a page even if there is no edit
permisson. It is also possible to create an "orphaned attached file" (e.g.
by manual entering an URL like
http://my.example.com/wicked/display.php?page=AttachedFiles&referrer=T123It
where the page T123It doesn't exist).
The patch should solve these probs.
More information about the bugs
mailing list