rave-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Matt Franklin (Commented) (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (RAVE-568) Widgets with preview-status can still be added
Date Fri, 20 Apr 2012 12:52:40 GMT

    [ https://issues.apache.org/jira/browse/RAVE-568?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13258201#comment-13258201

Matt Franklin commented on RAVE-568:

So the search and category selection behaviors sound like bugs.  I think we should add 2 new
jira issues:  

1) bug for filter applicaiton
2) new story to configure whether users can add widgets they put into the store to their page

If you have time to create and describe these issues that would be great.  If not, I will
try to do them later.
> Widgets with preview-status can still be added
> ----------------------------------------------
>                 Key: RAVE-568
>                 URL: https://issues.apache.org/jira/browse/RAVE-568
>             Project: Rave
>          Issue Type: Bug
>          Components: rave-core, rave-web
>    Affects Versions: 0.10.1
>            Reporter: Dennis van der Laan
> In the widget store, when using the category filter or 'my widgets' filter, widgets with
'preview' status are shown also. Users are able to add preview-widgets this way.
> Because users are also able to upload widgets, which then get preview-status, this seems
like a security issue.

This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira


View raw message