Anonymous | Login | Signup for a new account | 2024-03-29 09:14 CDT |
Main | My View | View Issues | Change Log | Roadmap | Docs | Wiki | Repositories |
Dependency Graph | [ View Issue ] [ Relation Graph ] [ Vertical ] | |||
|
||||
|
Viewing Issue Simple Details | |||||
ID | Category | Type | Reproducibility | Date Submitted | Last Update |
0000025 | [In-Portal CMS] Security | bug report | always | 2009-05-20 14:50 | 2009-10-03 07:56 |
Reporter | alex | View Status | public | ||
Assigned To | alex | ||||
Priority | normal | Resolution | fixed | ||
Status | closed | ||||
Summary | 0000025: Non-root user can't use copy/cut/paste buttons in catalog. | ||||
Description |
For 5.0.0 release permission checking for category items and categories was changed. Now all events in temp tables are allowed, but other events (specified in event handler) are checked by individual logic. Problem is, that OnCut, OnCopy, OnPaste, OnPasteClipboard events are not specified at all and that's why are denied for execution in any circumstances. What permissions should be checked: OnCut - delete right in category, where cut button was pressed. OnCopy - no permission required, because it doesn't change data. OnPaste, OnPasteClipboard - add right for category, where paste is performed. |
||||
Additional Information |
Main | My View | View Issues | Change Log | Roadmap | Docs | Wiki | Repositories |
Web Development by Intechnic In-Portal Open Source CMS |