Gargaj / wuhu

Lightweight Party Management System
http://wuhu.function.hu/
Other
41 stars 26 forks source link

Timetable plugin does not appear to check logged in / authorized state #58

Open falken42 opened 2 years ago

falken42 commented 2 years ago

The Timetable plugin does not appear to properly check the logged in state of a user before displaying the timetable, even when the menu type for the Timetable plugin is set to "Logged in only".

While the top menu does not show a URL link to the Timetable page, anyone with access to the Timetable page URL will be able to view the timetable without logging in. Other pages (such as Voting) properly show an expected UNAUTHORIZED REQUEST! error.

Screen Shot 2021-11-14 at 14 41 11 Screen Shot 2021-11-14 at 14 41 35