Fossil SCM

* Fixed security bug in ticket reports, you previously had to have Check-out security to view a ticket report, you now have to have "r" (Read-tkt) to view ticket reports.

jeremy_c 2009-12-31 14:49 trunk
Commit 6ee7316567a60422d1bb66edd9b883eebb6e3009
1 file changed +1 -1
+1 -1
--- src/report.c
+++ src/report.c
@@ -873,11 +873,11 @@
873873
Stmt q;
874874
char *zErr1 = 0;
875875
char *zErr2 = 0;
876876
877877
login_check_credentials();
878
- if( !g.okRead ){ login_needed(); return; }
878
+ if( !g.okRdTkt ){ login_needed(); return; }
879879
rn = atoi(PD("rn","0"));
880880
if( rn==0 ){
881881
cgi_redirect("reportlist");
882882
return;
883883
}
884884
--- src/report.c
+++ src/report.c
@@ -873,11 +873,11 @@
873 Stmt q;
874 char *zErr1 = 0;
875 char *zErr2 = 0;
876
877 login_check_credentials();
878 if( !g.okRead ){ login_needed(); return; }
879 rn = atoi(PD("rn","0"));
880 if( rn==0 ){
881 cgi_redirect("reportlist");
882 return;
883 }
884
--- src/report.c
+++ src/report.c
@@ -873,11 +873,11 @@
873 Stmt q;
874 char *zErr1 = 0;
875 char *zErr2 = 0;
876
877 login_check_credentials();
878 if( !g.okRdTkt ){ login_needed(); return; }
879 rn = atoi(PD("rn","0"));
880 if( rn==0 ){
881 cgi_redirect("reportlist");
882 return;
883 }
884

Keyboard Shortcuts

Open search /
Next entry (timeline) j
Previous entry (timeline) k
Open focused entry Enter
Show this help ?
Toggle theme Top nav button