mahara-contributors team mailing list archive
-
mahara-contributors team
-
Mailing list archive
-
Message #03711
[Bug 771592] Re: Edit permission not checked in newviewtoken.json.php
** Changed in: mahara
Status: In Progress => Fix Committed
** Changed in: mahara
Milestone: None => 1.4.0
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
https://bugs.launchpad.net/bugs/771592
Title:
Edit permission not checked in newviewtoken.json.php
Status in Mahara ePortfolio:
Fix Committed
Status in Mahara 1.2 series:
Fix Released
Status in Mahara 1.3 series:
Fix Released
Bug description:
On master, the script is no longer used and should be deleted altogether.
On 1.2/1.3, we need to check that the logged in user has permission to edit the view.