プロジェクト

全般

プロフィール

Vote #81394

完了

Permission check of the setting button on the issues page mismatches button semantics

Admin Redmine さんが3年以上前に追加. 3年以上前に更新.

ステータス:
Closed
優先度:
通常
担当者:
-
カテゴリ:
UI_10
対象バージョン:
開始日:
2022/05/09
期日:
進捗率:

0%

予定工数:
category_id:
10
version_id:
171
issue_org_id:
35090
author_id:
3866
assigned_to_id:
332
comments:
7
status_id:
5
tracker_id:
1
plus1:
0
affected_version:
closed_on:
affected_version_id:
152
ステータス-->[Closed]

説明

In source:/tags/4.2.0/app/views/issues/index.html.erb#L16 the link goes to the @issues@ tab of the project settings. The button is only shown if the user has the @manage_categories@ permission but the permission required for this tab is @edit_project@ source:/tags/4.2.0/app/helpers/projects_helper.rb#L28

Note that this is only a UI issue, the button might be shown to users that cannot see the tab that it links to or the button might not be shown to users that would be able to see the tab that it links too, but upon following the link the correct permission is checked. There also is no information disclosure associated with this issue.


journals

--------------------------------------------------------------------------------
I made a patch to fix & test the issue #35090, and attach it.
--------------------------------------------------------------------------------

--------------------------------------------------------------------------------
Setting the target version to 4.1.5.
--------------------------------------------------------------------------------
Committed the patch. Thank you for your contribution.
--------------------------------------------------------------------------------

--------------------------------------------------------------------------------


related_issues

relates,Closed,22090,Make project settings more accessible

Admin Redmine さんが3年以上前に更新

  • カテゴリUI_10 にセット
  • 対象バージョン4.1.6_171 にセット

他の形式にエクスポート: Atom PDF

いいね!0
いいね!0