Modify

Opened 15 years ago

Closed 15 years ago

#6584 closed defect (invalid)

Ticket Restrictions have no effect on Download Formats

Reported by: akkarin@… Owned by: Noah Kantrowitz
Priority: highest Component: PrivateTicketsPlugin
Severity: blocker Keywords:
Cc: akkarin@… Trac Release: 0.11

Description

I have multiple different levels of access levels, but even an anonymous user can select the "Download in other formats:" (e.g. CSV) and get a full ticket listing.

Attachments (0)

Change History (3)

comment:1 Changed 15 years ago by itai@…

Priority: highhighest

We have the same problem, users with limited permission are able to download a CSV file via the "Download in other formats" seeing all tickets ever created. This is a serious security hole.

comment:2 Changed 15 years ago by anonymous

Severity: criticalblocker

comment:3 Changed 15 years ago by Noah Kantrowitz

Resolution: invalid
Status: newclosed

Not a but in the plugin. This was a bug in Trac itself, but I'm told it has since been corrected.

Modify Ticket

Change Properties
Set your email in Preferences
Action
as closed The owner will remain Noah Kantrowitz.
The resolution will be deleted. Next status will be 'reopened'.

Add Comment


E-mail address and name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.