Page MenuHomePhabricator

Don't skip policy checks on ObjectQuery if special capabilities are required
ClosedPublic

Authored by epriestley on Dec 17 2014, 11:44 PM.
Tags
None
Referenced Files
F15418677: D11005.id26430.diff
Fri, Mar 21, 12:46 AM
F15415606: D11005.id26430.diff
Thu, Mar 20, 6:53 AM
F15413896: D11005.id26428.diff
Wed, Mar 19, 9:52 PM
F15411848: D11005.id.diff
Wed, Mar 19, 10:02 AM
F15406614: D11005.diff
Tue, Mar 18, 12:53 PM
F15404601: D11005.diff
Tue, Mar 18, 8:24 AM
F15375422: D11005.id.diff
Wed, Mar 12, 11:09 PM
Unknown Object (File)
Feb 8 2025, 12:22 AM
Subscribers

Details

Summary

Ref T6741. As an optimization, we omit policy checks on ObjectQuery, but need to retain them if the query requests non-view permissions. This primarily affected Almanac properties.

Test Plan

Almanac properties now do full policy checks on ObjectQuery loads.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

epriestley retitled this revision from to Don't skip policy checks on ObjectQuery if special capabilities are required.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added a reviewer: btrahan.
btrahan edited edge metadata.
This revision is now accepted and ready to land.Dec 18 2014, 12:47 AM
This revision was automatically updated to reflect the committed changes.