comparison doc/implementation.txt @ 4437:261c9f913ff7

- Add explicit "Search" permissions, see Security Fix below. - Security Fix: Add a check for search-permissions: now we allow searching for properties only if the property is readable without a check method or if an explicit search permission (see above unter "Features) is given for the property. This fixes cases where a user doesn't have access to a property but can deduce the content by crafting a clever search, group or sort query. see doc/upgrading.txt for how to fix your trackers!
author Ralf Schlatterbeck <schlatterbeck@users.sourceforge.net>
date Tue, 19 Oct 2010 15:29:05 +0000
parents b9c1226cb600
children 33a1f03b9de0
comparison
equal deleted inserted replaced
4436:528ace81fd16 4437:261c9f913ff7

Roundup Issue Tracker: http://roundup-tracker.org/