<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>CKAN: Ticket #1027: Authorization checks on all controller actions</title>
    <link>http://localhost/ticket/1027</link>
    <description>&lt;p&gt;
We want to have authz checks on all controller actions so that we can lock down CKAN to a login-only mode.
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>CKAN</title>
      <url>http://assets.okfn.org/p/ckan/img/ckan_logo_shortname.png</url>
      <link>http://localhost/ticket/1027</link>
    </image>
    <generator>Trac 0.12.3</generator>
    <item>
      
        <dc:creator>pudo</dc:creator>

      <pubDate>Wed, 09 Mar 2011 10:25:26 GMT</pubDate>
      <title>status changed</title>
      <link>http://localhost/ticket/1027#comment:1</link>
      <guid isPermaLink="false">http://localhost/ticket/1027#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;assigned&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;ol&gt;&lt;li&gt;home controller -&amp;gt; &lt;span class="underline"&gt;before&lt;/span&gt; (check "site-read" on model.System)
&lt;/li&gt;&lt;li&gt;user -&amp;gt; each individually (repoze-who pseudo action must not be blocked)
&lt;ul&gt;&lt;li&gt;user-read (index/read/update pages for users)
&lt;/li&gt;&lt;li&gt;user-create (register)
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;revision -&amp;gt; &lt;span class="underline"&gt;before&lt;/span&gt; (check "site-read" on model.System)
&lt;/li&gt;&lt;li&gt;tag -&amp;gt; site-read (&lt;span class="underline"&gt;before&lt;/span&gt;)
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
functional/test_authz.py
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;denies site-read ...
&lt;/li&gt;&lt;li&gt;checks for visitor / logged in user ..
&lt;/li&gt;&lt;li&gt;checks you can still visit login
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>pudo</dc:creator>

      <pubDate>Wed, 09 Mar 2011 14:48:02 GMT</pubDate>
      <title>status changed; resolution set</title>
      <link>http://localhost/ticket/1027#comment:2</link>
      <guid isPermaLink="false">http://localhost/ticket/1027#comment:2</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;assigned&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
fixed in cset:532c3ad2743b
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>