comparison scripts/copy-user.py @ 4088:34434785f308

Plug a number of security holes: - EditCSV and ExportCSV altered to include permission checks - HTTP POST required on actions which alter data - HTML file uploads served as application/octet-stream - New item action reject creation of new users - Item retirement was not being controlled Additionally include documentation of the changes and modify affected tests.
author Richard Jones <richard@users.sourceforge.net>
date Thu, 12 Mar 2009 02:25:03 +0000
parents bd9e2e998e9d
children 6e3e4f24c753
comparison
equal deleted inserted replaced
4087:1d0d1921f083 4088:34434785f308

Roundup Issue Tracker: http://roundup-tracker.org/