Project

General

Profile

« Previous | Next » 

Revision ce13ab5d

Added by Marek Hulán over 10 years ago

fixes #2863 - restrict APIs to resources that a user is permitted to manage (CVE-2013-4182)

View differences:

test/unit/organization_test.rb
assert_equal used_ids[:domain_ids].sort, Array(domains(:mydomain).id).sort
assert_equal used_ids[:medium_ids].sort, Array.new
assert_equal used_ids[:compute_resource_ids].sort, Array(compute_resources(:one).id).sort
assert_equal used_ids[:user_ids], Array.new
assert_equal used_ids[:user_ids], [users(:restricted).id]
assert_equal used_ids[:smart_proxy_ids].sort, Array([smart_proxies(:one).id, smart_proxies(:two).id, smart_proxies(:three).id, smart_proxies(:puppetmaster).id]).sort
assert_equal used_ids[:config_template_ids].sort, Array(config_templates(:mystring2).id).sort
end

Also available in: Unified diff