Ref T13350. This ancient API method is missing modern policy checks.
Details
Details
- Reviewers
- None
- Maniphest Tasks
- T13350: Ancient "slowvote.info" API method bypasses policy checks
- Commits
- rP7e09da3313fb: Fix policy behavior of "slowvote.info" API method
- Set visibility of vote X to "Only: epriestley".
- Called "slowvote.info" as another user.
- Before: retrieved poll title and author.
- After: policy error.
- Called "slowvote.info" on a visible poll, got information before and after.
Diff Detail
Diff Detail
- Repository
- rP Phabricator
- Branch
- vote1x
- Lint
Lint Passed - Unit
Tests Passed - Build Status
Buildable 23195 Build 31860: Run Core Tests Build 31859: arc lint + arc unit