Opened 5 years ago

Last modified 3 years ago

#9965 assigned enhancement

Reports can consist of many pages with no entries

Reported by: rjollos Owned by: rjollos
Priority: normal Component: PrivateTicketsPlugin
Severity: normal Keywords: security
Cc: Trac Release: 0.12

Description (last modified by rjollos)

Here is Page 1 for Report {1}:

Pages 2 and 4 look the same as Page 1.

Here is Page 3 for Report {1}:

It looks as though the page is rendered, and then all the tickets that are not viewable by this user are dropped. We need to figure out how to aggregate the entries to a single page, and only show a count that represents what the user can view. In fact, showing a count for a particular report that includes tickets a user cannot view might be considered a minor security hole.

Attachments (2)

Report1-Page1.png (21.8 KB) - added by rjollos 5 years ago.
Report1-Page3.png (34.7 KB) - added by rjollos 5 years ago.

Download all attachments as: .zip

Change History (5)

Changed 5 years ago by rjollos

Changed 5 years ago by rjollos

comment:1 Changed 5 years ago by rjollos

  • Description modified (diff)

comment:2 Changed 5 years ago by rjollos

Appears to be a duplicate of #3674. The corresponding ticket in the Trac core is t:#7608. If we close this as wontfix, then at the very least we should document the issue on the wiki page.

comment:3 Changed 3 years ago by rjollos

  • Status changed from new to assigned

Add Comment

Modify Ticket

as assigned The owner will remain rjollos.

E-mail address and user name can be saved in the Preferences.

Note: See TracTickets for help on using tickets.