Project

General

Profile

Actions

Refactor #3930

closed

editing_self permission check is 'global'

Added by Ohad Levy almost 11 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Authentication
Target version:
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

While this does not seems like a bug, the code in the permission checking system always validates if the user edit it self (so a non admin user can edit his account), but this code is checked globally for all permissions checks.

also, the normalization of controllers names is spread across the app.


Related issues 1 (0 open1 closed)

Blocks Foreman - Bug #3858: No menus shown for non-admin usersClosed12/11/2013Actions
Actions

Also available in: Atom PDF