Bug #37105

Using the Everybody Role in an ACL will result in dropped ACLs

Added by Christian Müller about 3 years ago. Updated about 3 years ago.

Status:Resolved Start date:2012-05-11
Priority:Must have Due date:
Assigned To:Christian Müller % Done:

100%

Category:Security
Target version:-
PHP Version: Complexity:
Has patch:No Affected Flow version:Git master

Description

PolicyService is reusing data for the same resource, unfortunately it can happen that this data is not the expected and so the resulting acls are not the ones configured.

Associated revisions

Revision a617bd03
Added by Christian Müller about 3 years ago

[BUGFIX] PolicyService could drop ACLs for overlapping resources

The PolicyService has to properly reuse all data gathered from
parsing the method resources, the traces were dropped for
different roles and so something wrong would be reused.

Change-Id: I4017e030ee2a1351a099006da65d5828b165f967
Fixes: #37105
Releases: 1.1

History

#1 Updated by Gerrit Code Review about 3 years ago

  • Status changed from Accepted to Under Review

Patch set 1 for branch master has been pushed to the review server.
It is available at http://review.typo3.org/11147

#2 Updated by Gerrit Code Review about 3 years ago

Patch set 2 for branch master has been pushed to the review server.
It is available at http://review.typo3.org/11147

#3 Updated by Gerrit Code Review about 3 years ago

Patch set 3 for branch master has been pushed to the review server.
It is available at http://review.typo3.org/11147

#4 Updated by Christian Müller about 3 years ago

  • Status changed from Under Review to Resolved
  • % Done changed from 0 to 100

Also available in: Atom PDF