Page MenuHomePhabricator

When creating a new Phame blog post, check that the author has permission to post to the blog
ClosedPublic

Authored by epriestley on Mar 6 2014, 2:54 PM.
Tags
None
Referenced Files
F18053605: D8423.id20014.diff
Mon, Aug 4, 5:14 AM
F18051474: D8423.id20014.diff
Sun, Aug 3, 11:24 PM
F18027464: D8423.id20001.diff
Sat, Aug 2, 10:31 PM
F18020727: D8423.id.diff
Sat, Aug 2, 7:54 PM
F17985071: D8423.diff
Fri, Aug 1, 8:38 PM
F17949282: D8423.diff
Thu, Jul 31, 11:08 PM
Unknown Object (File)
May 9 2025, 8:54 PM
Unknown Object (File)
May 6 2025, 7:46 AM
Subscribers

Details

Summary

Via HackerOne. We're missing this permissions check, so you can sneak around it.

Test Plan

Tried to post to a blog I had no permission to join.

Diff Detail

Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

btrahan edited edge metadata.

thanks!

This revision is now accepted and ready to land.Mar 6 2014, 9:57 PM

(This one was almost certainly my fault.)