Issue 497: Standard specific information object template names bypass security http://code.google.com/p/qubit-toolkit/issues/detail?id=497
New issue report by [EMAIL PROTECTED]: You can edit an information object without logging in by going to the "editISAD" (and presumably "editRAD", etc.) URL. e.g. http://localhost/~yourname/qubit/web/informationobject/editISAD/id/278 Issue attributes: Status: New Owner: vangarderen.peter Labels: Type-Defect Priority-Medium Milestone-Release-1.0.4 Security -- You received this message because you are listed in the owner or CC fields of this issue, or because you starred this issue. You may adjust your issue notification preferences at: http://code.google.com/hosting/settings --~--~---------~--~----~------------~-------~--~----~ You received this message because you are subscribed to the Google Groups "Qubit Toolkit Issues" group. To post to this group, send email to [email protected] To unsubscribe from this group, send email to [EMAIL PROTECTED] For more options, visit this group at http://groups.google.com/group/qubit-issues?hl=en -~----------~----~----~----~------~----~------~--~---
