See https://hackerone.com/reports/1573143. The pathway for disabling global builtin queries is missing a policy check. Add it.
Details
Details
- Accessed the "/search/delete/id/.../" URI for a global builtin query as a non-administrator.
- Before patch: could improperly disable queries. -After patch: proper policy exception.
Diff Detail
Diff Detail
- Repository
- rP Phabricator
- Branch
- query1
- Lint
Lint Passed - Unit
Tests Passed - Build Status
Buildable 25759 Build 35587: arc lint + arc unit