Page MenuHomePhabricator

When creating a new Phame blog post, check that the author has permission to post to the blog
ClosedPublic

Authored by epriestley on Mar 6 2014, 2:54 PM.
Tags
None
Referenced Files
F15450830: D8423.diff
Fri, Mar 28, 6:31 PM
F15433016: D8423.id20014.diff
Mon, Mar 24, 8:53 PM
F15424148: D8423.id20001.diff
Sat, Mar 22, 8:33 PM
F15398271: D8423.id20014.diff
Sun, Mar 16, 11:55 PM
Unknown Object (File)
Jan 31 2025, 6:51 PM
Unknown Object (File)
Jan 23 2025, 3:29 PM
Unknown Object (File)
Jan 17 2025, 9:10 PM
Unknown Object (File)
Jan 17 2025, 2:32 AM
Subscribers

Details

Summary

Via HackerOne. We're missing this permissions check, so you can sneak around it.

Test Plan

Tried to post to a blog I had no permission to join.

Diff Detail

Repository
rP Phabricator
Branch
phame
Lint
Lint Passed
Unit
No Test Coverage

Event Timeline

btrahan edited edge metadata.

thanks!

This revision is now accepted and ready to land.Mar 6 2014, 9:57 PM

(This one was almost certainly my fault.)