Page MenuHomePhabricator

When creating a new Phame blog post, check that the author has permission to post to the blog
ClosedPublic

Authored by epriestley on Mar 6 2014, 2:54 PM.
Tags
None
Referenced Files
F14706708: D8423.diff
Fri, Jan 17, 2:32 AM
Unknown Object (File)
Mon, Jan 13, 9:31 PM
Unknown Object (File)
Sun, Jan 5, 12:22 PM
Unknown Object (File)
Tue, Dec 24, 11:47 AM
Unknown Object (File)
Fri, Dec 20, 4:37 PM
Unknown Object (File)
Dec 14 2024, 11:08 PM
Unknown Object (File)
Dec 12 2024, 9:21 PM
Unknown Object (File)
Dec 11 2024, 1:06 PM
Subscribers

Details

Summary

Via HackerOne. We're missing this permissions check, so you can sneak around it.

Test Plan

Tried to post to a blog I had no permission to join.

Diff Detail

Repository
rP Phabricator
Branch
phame
Lint
Lint Passed
Unit
No Test Coverage

Event Timeline

btrahan edited edge metadata.

thanks!

This revision is now accepted and ready to land.Mar 6 2014, 9:57 PM

(This one was almost certainly my fault.)