http://hg.code.sf.net:8000/p/roundup/code/atom-log/tip/share/roundup/templates/minimal/schema.py Mercurial Repository: p/roundup/code: share/roundup/templates/minimal/schema.py history 2024-12-21T15:23:12-05:00 chore: format schema.pys in templates so ruff is ok. http://hg.code.sf.net:8000/p/roundup/code/#changeset-984bc9f94ec65be4ec22a729442c0204b4d9988f John Rouillard rouilj@ieee.org 2024-12-21T15:23:12-05:00 2024-12-21T15:23:12-05:00
changeset 984bc9f94ec6
branch
bookmark
tag
user John Rouillard <rouilj@ieee.org>
description chore: format schema.pys in templates so ruff is ok.

Also makes comparing them easier.
files
update Anonymous Create user to Register user permissions http://hg.code.sf.net:8000/p/roundup/code/#changeset-c087ad45bf4d52ebbeab6a7eb105104e1962a2d3 John Rouillard rouilj@ieee.org 2023-02-02T12:55:27-05:00 2023-02-02T12:55:27-05:00
changeset c087ad45bf4d
branch
bookmark
tag
user John Rouillard <rouilj@ieee.org>
description update Anonymous Create user to Register user permissions

the devel and responsive tracker templates still had the old Create
user permissions for the anonymous user. Replace with the Regiter
permission that has been the standard since 1.4.11 maybe.

Also update references to Create permission in comment for the Email
Access permission for anon user.
files
add permissions to control user of rest and xmlrpc API interfaces. http://hg.code.sf.net:8000/p/roundup/code/#changeset-94a7669677ae229ff639da90a98eee7f0392b171 John Rouillard rouilj@ieee.org 2019-09-27T23:29:59-04:00 2019-09-27T23:29:59-04:00
changeset 94a7669677ae
branch
bookmark
tag
user John Rouillard <rouilj@ieee.org>
description add permissions to control user of rest and xmlrpc API interfaces.

issue2551058: Add new permissions: 'Rest Access' and 'Xmlrpc Access'
to allow per-user access control to rest and xmlrpc interfaces using
roles.

Updated all schemas to add these new perms to all authenticated roles.

Error conditions in handle_xmlrpc were not working right in manual
testing. I tried to make it a little better, but I don't actually
understand how the fault xmlrpc object is supposed to be used. So I
may have messed something up. I'll try to ping the people who wrote
the xmlrpc code to have them review.
files
Security fix default user permissions http://hg.code.sf.net:8000/p/roundup/code/#changeset-a403c29ffaf90efc510e09aad06afeba9780d844 Ralf Schlatterbeck rsc@runtux.com 2014-07-04T15:32:28+02:00 2014-07-04T15:32:28+02:00
changeset a403c29ffaf9
branch
bookmark
tag
user Ralf Schlatterbeck <rsc@runtux.com>
description Security fix default user permissions

Default user permissions should not include all user attributes. We now
limit this to the username, realname and some further attributes
depending on the schema. Note that we no longer include the email
addresses, depending on your installation you may want to further
restrict this or add some attributes like ``address`` and
``alternate_addresses``.
files
Fix minimal template, which was failing with: http://hg.code.sf.net:8000/p/roundup/code/#changeset-0c54c846ea6a8709029d91d72a4bf5b012909094 anatoly techtonik techtonik@gmail.com 2013-01-14T17:48:51+03:00 2013-01-14T17:48:51+03:00
changeset 0c54c846ea6a
branch
bookmark
tag
user anatoly techtonik <techtonik@gmail.com>
description Fix minimal template, which was failing with:

C:\roundup>demo.py -t minimal
Traceback (most recent call last):
File "C:\roundup\demo\schema.py", line 64, in <module>
db.security.addPermissionToRole('Anonymous', 'Register', 'user')
File "C:\roundup\roundup\security.py", line 304, in addPermissionToRole
properties, check)
File "C:\roundup\roundup\security.py", line 148, in getPermission
raise ValueError, 'No permission "%s" defined'%permission
ValueError: No permission "Register" defined
files
Fix security hole allowing user permission escalation http://hg.code.sf.net:8000/p/roundup/code/#changeset-b30bdfae44611d039899e17c1107163c7fa829ac Richard Jones richard@users.sourceforge.net 2009-12-20T23:24:21+00:00 2009-12-20T23:24:21+00:00
changeset b30bdfae4461
branch
bookmark
tag
user Richard Jones <richard@users.sourceforge.net>
description Fix security hole allowing user permission escalation

(thanks Ralf Schlatterbeck)

also update docs and prepare for a release
files
Fix issue2550553. http://hg.code.sf.net:8000/p/roundup/code/#changeset-42331c201b024cab413e373606c934033afc8191 Stefan Seefeld stefan@seefeld.name 2009-06-30T01:41:11+00:00 2009-06-30T01:41:11+00:00
changeset 42331c201b02
branch
bookmark
tag
user Stefan Seefeld <stefan@seefeld.name>
description Fix issue2550553.
files
Move templates/ to share/roundup/templates/ http://hg.code.sf.net:8000/p/roundup/code/#changeset-a6fdaaa3a8bd81128c87bb5aebc97bc13b44db1f Stefan Seefeld stefan@seefeld.name 2009-02-23T15:31:29+00:00 2009-02-23T15:31:29+00:00
changeset a6fdaaa3a8bd
branch
bookmark
tag
user Stefan Seefeld <stefan@seefeld.name>
description Move templates/ to share/roundup/templates/
files