http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=13663

--- Comment #9 from Alex Arnaud <[email protected]> ---
Oh yes, indeed, just seen that could be a security problem.
So, why not check only catalogue permission (Which is the one required to
access staff interface iirc)? I feel better with that because we won't need to
update upload-file.pl and upload-file-progress.pl permissions each time we add
a new page requiring these files with an other permission.

-- 
You are receiving this mail because:
You are watching all bug changes.
_______________________________________________
Koha-bugs mailing list
[email protected]
http://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs
website : http://www.koha-community.org/
git : http://git.koha-community.org/
bugs : http://bugs.koha-community.org/

Reply via email to