Project

General

Profile

bug #7360

users NOT having DELETE are permitted to delete References

Added by Andreas Kohlbecker 8 months ago. Updated 8 months ago.

Status:
Closed
Priority:
Highest
Category:
cdmlib
Target version:
Start date:
04/20/2018
Due date:
% Done:

100%

Severity:
critical
Found in Version:
Tags:

Description

A user which is not having the GrantedAuthority REFERENCE.[DELETE] or an according per entity permission is permitted to delete References

Associated revisions

Revision 2d55550d (diff)
Added by Andreas Kohlbecker 8 months ago

fix #7360 ReferenceVoter must never consider references orphan and thus allow deletion

Revision cc3d53cd (diff)
Added by Andreas Kohlbecker 8 months ago

ref #7360 also TaxonNames must never be orphan

History

#1 Updated by Andreas Kohlbecker 8 months ago

  • Status changed from New to Resolved
  • % Done changed from 0 to 50

#2 Updated by Andreas Kohlbecker 8 months ago

  • Status changed from Resolved to Closed
  • % Done changed from 50 to 100

solved for ReferenceVoter and for TaxonNameVoter

Also available in: Atom PDF

Add picture from clipboard (Maximum size: 40 MB)