Modify

Opened 7 years ago

Closed 7 years ago

Last modified 7 years ago

#1585 closed defect (fixed)

Calender Plugin should somehow honor Cal_Permissions

Reported by: jc@… Owned by: ant_39
Priority: highest Component: CalendarPlugin
Severity: normal Keywords: security, permission
Cc: Trac Release: 0.10

Description

I've set no permission to anonymous, but anonymous is able to see the calendar.
And also to edit the thing...

But cool plugin.

PS: where to switch off the Image while working (and is it needed anyway?)

Attachments (1)

Calendar.diff (3.3 KB) - added by jc@… 7 years ago.
Calendar Diff for azcalendar

Download all attachments as: .zip

Change History (7)

comment:1 Changed 7 years ago by anonymous

  • Component changed from TracHacks to CalendarPlugin
  • Owner changed from athomas to ant_39

comment:2 Changed 7 years ago by ant_39

  • Status changed from new to assigned

Indeed it should. I agree it's very feature-incomplete security-wise at the moment.

comment:3 Changed 7 years ago by totti

  • Keywords security permission added
  • Priority changed from normal to highest

is there anybody still working on this permission issue or do I have to disable this nice plugin?

pls let me know
cheers
totti

comment:4 Changed 7 years ago by jc@…

I did it. (hopefully) So I added the permissions and it seems to work.
But I'm not THAT familiar with the Trac Style ;) so maybe I did it completely wrong... but seems to work.

The Diff is attached.

Changed 7 years ago by jc@…

Calendar Diff for azcalendar

comment:5 Changed 7 years ago by ant_39

  • Resolution set to fixed
  • Status changed from assigned to closed

Thanks, I applied the patch (r2515).

I'd like to consider it a first stab at solving the problem, because there are some issues that need to be resolved, e.g. how does ticket ownership enter into the picture, if there should be CC lists akin to bugzilla, user groups, etc. But that's for proposal on its own.

comment:6 Changed 7 years ago by ant_39

Oh, and one more note, if/when you send more patches, please try to keep the indentations in python files at four spaces :)

Add Comment

Modify Ticket

Action
as closed .
The resolution will be deleted. Next status will be 'reopened'.
Author


E-mail address and user name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.