Ticket #1052 (closed defect: fixed)

Opened 3 years ago

Last modified 3 years ago

Authz holes

Reported by: dread Owned by: dread
Priority: minor Milestone: ckan-v1.4-sprint-4
Component: ckan Keywords:
Cc: Repository: ckan
Theme: none

Description (last modified by dread) (diff)

No authz on:

  • Group creation/edit/listing
  • Package relationship create/edit/delete

Change History

comment:1 Changed 3 years ago by dread

  • Description modified (diff)

comment:2 Changed 3 years ago by dread

  • Description modified (diff)

comment:3 Changed 3 years ago by dread

  • Status changed from new to closed
  • Resolution set to fixed

Fixed in branch feature-DGU#889-authorization-in-lockdown and merged to default at cset:e6643cf1324c. Only remaining issue is listing in Web interface of package relationships, which shows links to packages even to ones you can't read.

Note: See TracTickets for help on using tickets.