Project

General

Profile

« Previous | Next » 

Revision 3b0b7cb4

Added by Marek Hulán over 10 years ago

fixes #2863 - restrict APIs to resources that a user is permitted to manage (CVE-2013-4182)

View differences:

test/fixtures/users.yml
last_login_on: 2009-10-12 21:50:04
auth_source: one
restricted:
login: restricted
firstname: Restricted
lastname: User
mail: userrestricted@someware.com
admin: false
last_login_on: 2009-10-12 21:50:04
auth_source: one
filter_on_owner: true
admin:
login: admin
firstname: Admin
......
last_login_on: 2009-10-12 21:50:04
auth_source: internal
password_hash: 02d7ff9921071af778ff4f8608579dcd6d80dfba
password_salt: 80a167f1effbd82c2485ed81c3cfd68b11bc40dc
password_salt: 80a167f1effbd82c2485ed81c3cfd68b11bc40dc

Also available in: Unified diff