#220: BibSched: bypass CFG_BIBTASK_VALID_TASKS check?
-----------------------+----------------------------------------------------
Reporter: jcaffaro | Owner: skaplun
Type: defect | Status: new
Priority: major | Milestone: v1.0
Component: BibSched | Version:
Resolution: | Keywords: BibTask
-----------------------+----------------------------------------------------
Changes (by skaplun):
* status: infoneeded_new => new
* milestone: => v1.0
Comment:
This is indeed a bug. Perfect security can not be enforced (as tasks can
behave as tasks without necessary importing the module bibtask.py).
However a further check can be added to be sure that python code that
pretend to be a bibtasks by using the bibtask module must also be
authorized through CFG_BIBTASK_VALID_TASKS.
--
Ticket URL: <http://invenio-software.org/ticket/220#comment:2>
Invenio <http://invenio-software.org>