<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>CKAN: Ticket #133: Security hole - search package/group (WUI &amp; REST)</title>
    <link>http://localhost/ticket/133</link>
    <description>&lt;p&gt;
Using WUI or REST interface you can search packages and groups without authorization being checked.
&lt;/p&gt;
&lt;p&gt;
On the REST interface you can also read all the attributes of the packages using the 'all-fields' option.
&lt;/p&gt;
&lt;p&gt;
Can be fixed using more advanced query to check authz.
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>CKAN</title>
      <url>http://assets.okfn.org/p/ckan/img/ckan_logo_shortname.png</url>
      <link>http://localhost/ticket/133</link>
    </image>
    <generator>Trac 0.12.3</generator>
    <item>
      
        <dc:creator>dread</dc:creator>

      <pubDate>Fri, 07 May 2010 17:39:37 GMT</pubDate>
      <title>status changed; resolution set</title>
      <link>http://localhost/ticket/133#comment:1</link>
      <guid isPermaLink="false">http://localhost/ticket/133#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
WUI and REST interfaces recently updated. You can't read, list or search for packages or groups not-authorised for.
&lt;/p&gt;
&lt;p&gt;
The only remaining view of a non-authorised group is that the group is named when viewing a package using all_fields option in REST interface. But no details of other packages in the group are given.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>