← Back to team overview

mahara-contributors team mailing list archive

[Bug 1874530] Re: extracting a zipped file's contents not working correctly

 

Also noticed a problem

4) a user guessing file IDs can initiate a zip file extraction for
another user, eg hitting the page artefact/file/extract.php?file= with a
valid ID for a zip file

luckily the files get extracted to the zip file owner and not the hacker
but we need to fix that up as well as they can see a list of filenames
in the zip file

-- 
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: Subscription for all Mahara Contributors -- please ask on #mahara-dev or mahara.org forum before editing or unsubscribing it!
https://bugs.launchpad.net/bugs/1874530

Title:
  extracting a zipped file's contents not working correctly

Status in Mahara:
  In Progress

Bug description:
  This page needs some fixing up, the current problems are:

  1) The process bar is in the old css style and should be using the new
  colours and not have a scroll bar in it

  2) The general layout of the page could use some tidying up as well

  3) The extraction of files looks to work but there is no redirect back
  to files page (either automatically or via a button)

To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/1874530/+subscriptions


References