bgarrels / textpattern

Automatically exported from code.google.com/p/textpattern
0 stars 0 forks source link

has_privs() can return true when user does not have access #301

Closed GoogleCodeExporter closed 9 years ago

GoogleCodeExporter commented 9 years ago
This can happen if $txp_permissions array value contains an empty byte (0, '', 
false) or trailing comma.

If this ever happens, non-authenticated users and non-existing users have 
access to that specific resource.

This means that there is no way to set permissions completely off while still 
keeping the resource registered.

Original issue reported on code.google.com by jukka.m.svahn on 29 Oct 2012 at 9:03

GoogleCodeExporter commented 9 years ago
This issue was closed by revision r4511.

Original comment by jukka.m.svahn on 29 Oct 2012 at 9:19