camelcasetechsd / certigate

0 stars 0 forks source link

CGP149: [BUG] User can view other users details #149

Closed lebaz20 closed 8 years ago

lebaz20 commented 8 years ago

user details is accessed via url : /users/more/id using current user id or any other user id will just display that user details, although access forbidden should be thrown for users with different id than current user's if he/she is not admin 'has admin role'

ahmedReda1 commented 8 years ago