Modify

Opened 5 years ago

Closed 2 months ago

#9965 closed enhancement (cantfix)

Reports can consist of many pages with no entries

Reported by: Ryan J Ollos Owned by: Ryan J Ollos
Priority: normal Component: PrivateTicketsPlugin
Severity: normal Keywords: security
Cc: Trac Release: 0.12

Description (last modified by Ryan J Ollos)

Here is Page 1 for Report {1}:

Pages 2 and 4 look the same as Page 1.

Here is Page 3 for Report {1}:

It looks as though the page is rendered, and then all the tickets that are not viewable by this user are dropped. We need to figure out how to aggregate the entries to a single page, and only show a count that represents what the user can view. In fact, showing a count for a particular report that includes tickets a user cannot view might be considered a minor security hole.

Attachments (2)

Report1-Page1.png (21.8 KB) - added by Ryan J Ollos 5 years ago.
Report1-Page3.png (34.7 KB) - added by Ryan J Ollos 5 years ago.

Download all attachments as: .zip

Change History (6)

Changed 5 years ago by Ryan J Ollos

Attachment: Report1-Page1.png added

Changed 5 years ago by Ryan J Ollos

Attachment: Report1-Page3.png added

comment:1 Changed 5 years ago by Ryan J Ollos

Description: modified (diff)

comment:2 Changed 5 years ago by Ryan J Ollos

Appears to be a duplicate of #3674. The corresponding ticket in the Trac core is t:#7608. If we close this as wontfix, then at the very least we should document the issue on the wiki page.

comment:3 Changed 3 years ago by Ryan J Ollos

Status: newassigned

comment:4 Changed 2 months ago by Ryan J Ollos

Resolution: cantfix
Status: assignedclosed

Modify Ticket

Change Properties
Set your email in Preferences
Action
as closed The owner will remain Ryan J Ollos.
The resolution will be deleted. Next status will be 'reopened'.

Add Comment


E-mail address and name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.