Skip to content

Minor view hardening #12

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
1 commit merged into from
Sep 15, 2010
Merged

Minor view hardening #12

1 commit merged into from
Sep 15, 2010

Conversation

acdha
Copy link
Contributor

@acdha acdha commented Sep 15, 2010

Since these are behing @login_required it's probably not the end of the world for either of these to return error pages but it's more correct and conceivably could leak information with a compromised account, although that'd require some unusual circumstances

* jsapi now returns a HTTP 400 (bad request) instead of an exception
  when no op is specified
* group now returns a 404 rather than an exception if an invalid gid is
  passed to the view
@github-actions github-actions bot locked and limited conversation to collaborators Dec 24, 2020
This pull request was closed.
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant