https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=7550
--- Comment #4 from Marc Véron <[email protected]> --- Created attachment 62271 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=62271&action=edit Bug 7550 - Self checkout: limit display of patron image to logged-in patron The patron image display in the self-checkout takes a GET parameter from the image source, so if someone copied the image location and substituted the barcode string they could browse through all patron images: <img alt="" src="/cgi-bin/koha/sco/sco-patron-image.pl?borrowernumber=XXXX"> To reproduce: - Enable self checkout, go to [Your Server]//cgi-bin/koha/sco/sco-main.pl - Log in with a user 'A' who has a patron image - Copy the address of the patron image into an other browser window - Change the borrowernumber to on of an other user 'B' having a patron image - Verify that the patron image is displayed To test: - Apply patch, restart plack / memcached - Try to reproduce - Verify that you can no longer display the image of user 'B' by tweaking the image address - Log out user 'A' from SCO (click 'Finish') - Try to display image of user 'A', verify that it is not possible - Log out form SCO (go to an other OPAC page) - Try to display image of user 'A', verify that it is not possible -- You are receiving this mail because: You are watching all bug changes. _______________________________________________ Koha-bugs mailing list [email protected] http://lists.koha-community.org/cgi-bin/mailman/listinfo/koha-bugs website : http://www.koha-community.org/ git : http://git.koha-community.org/ bugs : http://bugs.koha-community.org/
