Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[2.3 beta] Authors can edit sections via "Edit Section" button #938

Closed
nickdunn opened this issue Dec 8, 2011 · 1 comment
Closed

[2.3 beta] Authors can edit sections via "Edit Section" button #938

nickdunn opened this issue Dec 8, 2011 · 1 comment
Assignees
Milestone

Comments

@nickdunn
Copy link
Contributor

nickdunn commented Dec 8, 2011

Has it always been the case that an Author (not Developer) can modify sections by guessing the URL?

In 2.3 beta there is an "Edit Section" button in the entry listing view which is shown to authors as well as developers, even though the Blueprints menu is hidden.

Edit: also, the "Sections" label in the breadcrumb on the section editor leads to a 404 for authors. So I'm guessing that they should never get here in the first place.

@brendo
Copy link
Member

brendo commented Dec 9, 2011

The button shouldn't appear to Authors, so that's the first bug.

The second is a familiar situation. Previously you could guess the URL of a hidden section for the entries table, in 2.2 I changed this behaviour so if a section was hidden, it'd 404. In 2.2.3 (IIRC), we reverted the behaviour back as we concluded that the hide/show feature is more of a visual thing, rather than enforcing access rules.

Editing sections is a whole different ball game though, so I agree, Authors shouldn't be allowed to guess such URL's.

@ghost ghost assigned brendo Dec 9, 2011
@brendo brendo closed this as completed in c67fc1e Dec 9, 2011
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants