#5294 Need to do permission checks on project REST controller

v1.0.0
closed
nobody
42cc (432)
General
2015-08-20
2012-11-14
No

http://sourceforge.net/rest/p/allura/ lists tools that are not public (e.g. private-tickets). This is a only minor security concern since we only expose the existence of such tools, the contents are already properly protected.

Related

Tickets: #5294

Discussion

  • Dave Brondsema

    Dave Brondsema - 2013-04-11
    • labels: --> 42cc
     
  • Igor Bondarenko - 2013-04-12
    • status: open --> in-progress
     
  • Igor Bondarenko - 2013-04-12

    Created #320: [#5294] Need to do permission checks on project REST controller (1cp)

     

    Related

    Tickets: #5294

  • Igor Bondarenko - 2013-04-22
    • status: in-progress --> code-review
     
  • Igor Bondarenko - 2013-04-22

    Closed #320. je/42cc_5294

     
  • Dave Brondsema

    Dave Brondsema - 2013-04-26
    • QA: Dave Brondsema
     
  • Dave Brondsema

    Dave Brondsema - 2013-04-26
    • status: code-review --> closed
     
  • Dave Brondsema

    Dave Brondsema - 2013-05-02
    • Milestone: forge-backlog --> forge-may-03
     

Log in to post a comment.