Resolve "Add argument to lesson events get_objects method that bypasses the filtering done if own=False" #716

Closed
yuha wants to merge 1 commit from 281-add-argument-to-lesson-events-get_objects-method-that-bypasses-the-filtering-done-if-own-false into master
yuha commented 2025-01-10 20:08:20 +01:00 (Migrated from edugit.org)

Closes #281

Closes #281
yuha commented 2025-01-10 20:08:20 +01:00 (Migrated from edugit.org)

assigned to @yuha

assigned to @yuha
yuha commented 2025-01-10 20:08:47 +01:00 (Migrated from edugit.org)

added 1 commit

  • f17cae7f - Add argument

Compare with previous version

added 1 commit <ul><li>f17cae7f - Add argument</li></ul> [Compare with previous version](/AlekSIS/official/AlekSIS-App-Chronos/-/merge_requests/412/diffs?diff_id=53398&start_sha=324a0bba6d8758897650df02ac7d1a234eeefeda)
yuha commented 2025-01-13 01:30:03 +01:00 (Migrated from edugit.org)

added 1 commit

  • ada55392 - Allow bypassing of permission checks and person-related filtering

Compare with previous version

added 1 commit <ul><li>ada55392 - Allow bypassing of permission checks and person-related filtering</li></ul> [Compare with previous version](/AlekSIS/official/AlekSIS-App-Chronos/-/merge_requests/412/diffs?diff_id=53485&start_sha=f17cae7f09240cebe5496b06ce57f0f136667b98)
yuha commented 2025-01-13 01:30:32 +01:00 (Migrated from edugit.org)

marked this merge request as ready

marked this merge request as **ready**
yuha commented 2025-01-13 01:30:58 +01:00 (Migrated from edugit.org)

mentioned in merge request AlekSIS-App-Alsijil!766

mentioned in merge request AlekSIS-App-Alsijil!766
hansegucker commented 2025-01-15 15:53:28 +01:00 (Migrated from edugit.org)

requested review from @nik

requested review from @nik
hansegucker commented 2025-01-15 15:53:30 +01:00 (Migrated from edugit.org)

unassigned @yuha

unassigned @yuha
hansegucker commented 2025-01-15 15:53:35 +01:00 (Migrated from edugit.org)

assigned to @hansegucker

assigned to @hansegucker
hansegucker commented 2025-01-15 15:53:49 +01:00 (Migrated from edugit.org)

@nik Please give your opinion whether this is valid.

@nik Please give your opinion whether this is valid.
nik commented 2025-01-22 20:31:40 +01:00 (Migrated from edugit.org)

That's entirely awkward and will certainly result in a CVe at some point.

That's entirely awkward and will certainly result in a CVe at some point.
hansegucker commented 2025-01-22 21:06:32 +01:00 (Migrated from edugit.org)

We should provide a get_objects for default filtering and permissions and additional get_all_objects (or similar) to get all objects. The filtering logic should be in shared methods.

We should provide a `get_objects` for default filtering and permissions and additional `get_all_objects` (or similar) to get all objects. The filtering logic should be in shared methods.
hansegucker (Migrated from edugit.org) closed this pull request 2025-06-22 20:33:01 +02:00

Pull request closed

Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aleksis/AlekSIS-App-Chronos!716
No description provided.