Page MenuHomePhabricator

When creating a new Phame blog post, check that the author has permission to post to the blog
ClosedPublic

Authored by epriestley on Mar 6 2014, 2:54 PM.
Tags
None
Referenced Files
Unknown Object (File)
Thu, Sep 5, 2:14 PM
Unknown Object (File)
Tue, Sep 3, 8:49 PM
Unknown Object (File)
Mon, Aug 26, 3:17 AM
Unknown Object (File)
Sun, Aug 25, 9:22 PM
Unknown Object (File)
Aug 19 2024, 1:23 AM
Unknown Object (File)
Aug 17 2024, 5:31 AM
Unknown Object (File)
Aug 13 2024, 11:15 PM
Unknown Object (File)
Aug 9 2024, 4:04 AM
Subscribers

Details

Summary

Via HackerOne. We're missing this permissions check, so you can sneak around it.

Test Plan

Tried to post to a blog I had no permission to join.

Diff Detail

Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

btrahan edited edge metadata.

thanks!

This revision is now accepted and ready to land.Mar 6 2014, 9:57 PM

(This one was almost certainly my fault.)