Skip to content
This repository was archived by the owner on Apr 25, 2018. It is now read-only.

Conversation

@nghenglim
Copy link

Thanks for the good plugin. I'm currently learning myself cakePHP from PHP through implementing plugin.

I've seen that in the code, a visitor may delete a notification through random insert the notification ID ( success rate may increase when the user database grow). Here's some quick fix, still some modification can be applied into it to allow admin deletion.

added isOwnedBy function(which may be included in parent AppModel)
Fixed Security problem that visitor can delete particular notification.
@Oxicode
Copy link

Oxicode commented Jul 11, 2014

+1

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants