#6482: Auth Bug
---------------------------+------------------------------------------------
    Reporter:  qq71151461  |          Type:  Bug     
      Status:  new         |      Priority:  Critical
   Milestone:  1.2.x.x     |     Component:  General 
     Version:  1.2 Final   |      Severity:  Normal  
    Keywords:              |   Php_version:  n/a     
Cake_version:              |  
---------------------------+------------------------------------------------
 I update the code from SVN -8207. The AuthComponent has a bug.
 Line 298-301

 {{{
 $isAllowed = (
 $this->allowedActions == array('*') ||
 isset($methods[$controllerAction])
 );
 }}}

 The params $isAllowed always return true.

 I think the corrent code is

 {{{
 $isAllowed = (
 $this->allowedActions == array('*') ||
 in_array($controllerAction, $this->allowedActions)
 );
 }}}

-- 
Ticket URL: <https://trac.cakephp.org/ticket/6482>
CakePHP : The Rapid Development Framework for PHP <https://trac.cakephp.org/>
Cake is a rapid development framework for PHP which uses commonly known design 
patterns like ActiveRecord, Association Data Mapping, Front Controller and MVC. 
Our primary goal is to provide a structured framework that enables PHP users at 
all levels to rapidly develop robust web applications, without any loss to 
flexibility.
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"tickets cakephp" group.
To post to this group, send email to tickets-cakephp@googlegroups.com
To unsubscribe from this group, send email to 
tickets-cakephp+unsubscr...@googlegroups.com
For more options, visit this group at 
http://groups.google.com/group/tickets-cakephp?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to