-
Notifications
You must be signed in to change notification settings - Fork 95
fix_62782_62796 #1921
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix_62782_62796 #1921
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -1358,7 +1358,7 @@ def _get_shared_user_ids_from_list(shared_user_ids_list): | |
| # if exist shared_user_ids or owner allow to access | ||
| if int(cur_user) == int(activity_owner): | ||
| return 0 | ||
|
|
||
| if proxy_posting: | ||
| # If current user is in activity_user_ids or temp_user_ids | ||
| if int(cur_user) in activity_user_ids + temp_user_ids: | ||
|
|
@@ -2802,6 +2802,7 @@ def save_item_application(activity_id='0', action_id='0'): | |
| @workflow_blueprint.route('/get_feedback_maillist/<string:activity_id>', | ||
| methods=['GET']) | ||
| @login_required | ||
| @check_authority | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. issue (bug_risk): Applying Triggers: When an authenticated client requests Suggested fix: Return a 404 or the endpoint's existing error response when There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. issue (bug_risk): Unauthorized users are rejected by Triggers: When a logged-in user is denied by the workflow action authority check. Suggested fix: Return the JSON response with HTTP status 403, for example |
||
| def get_feedback_maillist(activity_id='0'): | ||
| """アクティビティに設定されているフィードバックメール送信先の情報を取得して返す | ||
|
|
||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
issue (testing):
check_index_permissionreads onlykwargsforindex_idandpath_str, so direct positional calls such as the existingjournal_detail(33)andget_path_name_dict('33_44')tests have neither value and abort with 404 instead of invoking the view.Triggers: When these decorated views are called positionally, as in the existing unit tests or any non-routing caller.
Suggested fix: Accept the corresponding positional arguments or update the decorator to bind arguments using the wrapped function signature before checking them.