[Tickets #1880] NEW: AttachedFile.php should respect permissions

bugs@bugs.horde.org bugs at bugs.horde.org
Thu Apr 28 02:36:09 PDT 2005


DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/?id=1880
-----------------------------------------------------------------------
 Ticket             | 1880
 Created By         | tasin at fhm.edu
 Summary            | AttachedFile.php should respect permissions 
 Queue              | Wicked
 State              | Unconfirmed
 Priority           | 2. Medium
 Type               | Bug
 Owners             | 
+New Attachment     | wicked1.diff
-----------------------------------------------------------------------


tasin at fhm.edu (2005-04-28 02:36) wrote:

Like Bug #915 only for attaching files.

Actually it is possible to attach files to a page even if there is no edit
permisson. It is also possible to create an "orphaned attached file" (e.g.
by manual entering an URL like
http://my.example.com/wicked/display.php?page=AttachedFiles&referrer=T123It
where the page T123It doesn't exist).
The patch should solve these probs.






More information about the bugs mailing list