You are here: Foswiki>Tasks Web>Item15024 (28 Mar 2022, MichaelDaum)Edit Attach

Item15024: QUERY macro does not check access rights

Priority: Security
Current State: Closed
Released In: 2.1.7
Target Release: patch
Applies To: Engine
Component: QUERY
Branches: Release02x01 master
Reported By: MichaelDaum
Waiting For:
Last Change By: MichaelDaum
How to reproduce:

  • create a topic with view restrictions
  • test view access ... blocked
  • test access via FORMFIELD ... blocked
  • test access via INCLUDE ... blocked
  • test access via QUERY ... no blocked

-- MichaelDaum - 06 May 2021

Topic revision: r2 - 28 Mar 2022, MichaelDaum
The copyright of the content on this website is held by the contributing authors, except where stated elsewhere. See Copyright Statement. Creative Commons License    Legal Imprint    Privacy Policy