bug #7360
users NOT having DELETE are permitted to delete References
Start date:
04/20/2018
Due date:
% Done:
100%
Severity:
critical
Found in Version:
Description
A user which is not having the GrantedAuthority REFERENCE.[DELETE]
or an according per entity permission is permitted to delete References
Associated revisions
fix #7360 ReferenceVoter must never consider references orphan and thus allow deletion
ref #7360 also TaxonNames must never be orphan
History
#1 Updated by Andreas Kohlbecker 10 months ago
- Status changed from New to Resolved
- % Done changed from 0 to 50
Applied in changeset cdmlib|2d55550d9d00f88e4f3e9e9a235f427914aa733e.
#2 Updated by Andreas Kohlbecker 10 months ago
- Status changed from Resolved to Closed
- % Done changed from 50 to 100
solved for ReferenceVoter and for TaxonNameVoter