is_none predicate is actually is_not_none #140

Closed
opened 2021-02-26 17:03:08 +01:00 by hansegucker · 7 comments
Owner

The predicate actually checks if an object is not none, but of course it should check if an object is none. This also breaks at least one permission rule, so this is very urgent and security-related.

(No worries, I fixed it in our production environment.)

The predicate actually checks if an object is **not** none, but of course it should check if an object is none. This also breaks at least one permission rule, so this is very urgent and security-related. (No worries, I fixed it in our production environment.)
Author
Owner

created merge request hansegucker/AlekSIS-App-Alsijil!391 to address this issue

created merge request hansegucker/AlekSIS-App-Alsijil!391 to address this issue
Author
Owner

made the issue visible to everyone

made the issue visible to everyone
Author
Owner

created merge request !535 to address this issue

created merge request !535 to address this issue
Author
Owner

mentioned in merge request !535

mentioned in merge request !535
Owner

Please always report security issues as confidential!

Please *always* report security issues as confidential!
nik closed this issue 2021-02-26 18:21:53 +01:00
Owner

mentioned in commit 654a975888

mentioned in commit 654a9758889ed89fcdeb40bc78e966b78eb33ae6
Author
Owner

I did so, but I wasn't able to create a related MR, so I made it visible.

I did so, but I wasn't able to create a related MR, so I made it visible.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
aleksis/AlekSIS-App-Alsijil#140
No description provided.