Uploaded image for project: 'JCommune'
  1. JCommune
  2. JC-954

Security improvements for DELETE action

VotersWatchers
    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed (View Workflow)
    • Priority: Critical
    • Resolution: Fixed
    • Affects Version/s: 0.20 Larks
    • Fix Version/s: 0.20 Larks
    • Labels:
      None

      Description

      1. Send DELETE to uat.jtalks.org/jcommune/components without authorization (you can use some programs like this one)

      Actual Result: response is OK, all topics are deleted.
      Expected: Authorization error should happen.

      Acceptance Criteria:
      DELETE request should remove branch/section/component content (topics & posts) if it was triggered from the same machine.
      DELETE request should not have affect if the request was sent from another IP.

        Attachments

          Issue Links

            Structure

              Activity

                People

                • Assignee:
                  yacov Iakov Volfkovich
                  Reporter:
                  julik Julia Atlygina
                • Votes:
                  0 Vote for this issue
                  Watchers:
                  4 Start watching this issue

                  Dates

                  • Due:
                    Created:
                    Updated:
                    Resolved:

                    Time Tracking

                    Estimated:
                    Original Estimate - 2h Original Estimate - 2h
                    2h
                    Remaining:
                    Remaining Estimate - 0h
                    0h
                    Logged:
                    Time Spent - 5.5h
                    5.5h

                      Structure Helper Panel