Page MenuHomePhabricator

When creating a new Phame blog post, check that the author has permission to post to the blog
ClosedPublic

Authored by epriestley on Mar 6 2014, 2:54 PM.
Tags
None
Referenced Files
F15482623: D8423.id20001.diff
Wed, Apr 9, 6:40 AM
F15481228: D8423.id20014.diff
Tue, Apr 8, 7:11 PM
F15480998: D8423.id20001.diff
Tue, Apr 8, 5:43 PM
F15478122: D8423.id20001.diff
Mon, Apr 7, 8:41 PM
F15477880: D8423.id.diff
Mon, Apr 7, 6:35 PM
F15475379: D8423.diff
Sun, Apr 6, 7:22 PM
F15450830: D8423.diff
Fri, Mar 28, 6:31 PM
F15433016: D8423.id20014.diff
Mon, Mar 24, 8:53 PM
Subscribers

Details

Summary

Via HackerOne. We're missing this permissions check, so you can sneak around it.

Test Plan

Tried to post to a blog I had no permission to join.

Diff Detail

Repository
rP Phabricator
Branch
phame
Lint
Lint Passed
Unit
No Test Coverage

Event Timeline

btrahan edited edge metadata.

thanks!

This revision is now accepted and ready to land.Mar 6 2014, 9:57 PM

(This one was almost certainly my fault.)