Modify

Opened 13 years ago

Closed 9 years ago

Last modified 6 years ago

#1 closed defect (fixed)

TracPermissions are not enforced in the PollMacro

Reported by: Alec Thomas Owned by: Alec Thomas
Priority: high Component: PollMacro
Severity: major Keywords: permissions
Cc: halkeye@… Trac Release: 0.8

Description

TracPermissions are not enforced in the PollMacro. The poll should not be modifiable if the user does not have write access to the page.

Attachments (0)

Change History (15)

comment:1 Changed 13 years ago by evan.s@…

This might be better as an option, as we only allow developers to modify the wiki but I can imagine a general poll being useful

comment:2 Changed 12 years ago by Alec Thomas

milestone: 1.00.9
version: 0.1stable

comment:3 Changed 12 years ago by halkeye

Cc: halkeye@… added; anonymous removed
Summary: TracPermissions are not enforced in the PollMacro

something along what AddCommentMacro uses? the appendonly parameter?

I was thinking about adding a showcount or something so you don't see the list of users.

comment:4 Changed 12 years ago by Alec Thomas

Yes, permissions like AddCommentMacro were what I was thinking of. The showcount idea would be difficult to achieve, as the comments are just added to the body of the page like a normal Wiki edit. It could be an idea though.

comment:5 Changed 12 years ago by halkeye

showcount wouldn't be that hard actually, the results are not in the body of the post, they are in a seperate file that you specify at the top of the wiki macro.

http://darkwarriors.kodekoan.com/cgi-bin/trac.cgi/wiki/ideaCombatXP?action=edit vs http://darkwarriors.kodekoan.com/cgi-bin/trac.cgi/wiki/ideaCombatXP

the data is not stored inside.

comment:6 Changed 12 years ago by Alec Thomas

Whoops, sorry about that...I was thinking of counting and AddCommentMacro :)

comment:7 Changed 12 years ago by Alec Thomas

Status: newassigned
Summary: TracPermissions are not enforced in the PollMacro

comment:8 Changed 12 years ago by Alec Thomas

#54 is related to this, but specifically regarding anonymous users.

comment:9 Changed 12 years ago by Alec Thomas

milestone: 0.9

Milestone 0.9 deleted

comment:10 Changed 12 years ago by Alec Thomas

Resolution: fixed
Status: assignedclosed
Trac Release: 0.8

Fixed when the PollMacro was ported to a plugin

comment:11 Changed 9 years ago by Ankur Goel

Resolution: fixed
Status: closedreopened

comment:12 Changed 9 years ago by Alec Thomas

Resolution: fixed
Status: reopenedclosed

Uh?

comment:13 Changed 9 years ago by anonymous

Resolution: fixed
Status: closedreopened

comment:14 Changed 9 years ago by anonymous

Resolution: fixed
Status: reopenedclosed

comment:15 Changed 6 years ago by zerodeux

(In [10765]) Basic support of JAR-like output format, need a better internal interface (cli or web should pick the filename and ask the export code to generate it), see #1

Modify Ticket

Change Properties
Set your email in Preferences
Action
as closed The owner will remain Alec Thomas.
The resolution will be deleted.

Add Comment


E-mail address and name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.