#322 - Restricted project tickets leaking

Description

What did you do to cause this?

I logged out and viewed the user page of a user with access to a restricted project.

What page were you on?

I was on the user page. Example. The "Staff Tracker" and associated tickets are part of a restricted project.

What PHP and MySQL versions do you run?

5.3.3-7+squeeze14, 5.1.66-0+squeeze1

Describe the defect:

Information meant to be private is leaking out through generally public pages. The information should be hidden from the user unless they have access to the group and tickets in question.

Activity

Jack closed as Fixed 12 years and 8 months ago

Status

Fixed
-
Normal

Details

Defect
3.0.7
Users
-
Normal

Tracking

Jamie R. McPeek
12 years and 8 months ago
11 years and 11 months ago
0
-
-