Blog entries can be commented on by non-member staff

Bug #360628 reported by Paul Everitt
2
Affects Status Importance Assigned to Milestone
KARL3
Fix Released
Medium
Tres Seaver

Bug Description

Create a new permission for comments.

Tags: security
Changed in karl3:
assignee: nobody → tseaver
importance: Undecided → Medium
milestone: none → m10
Revision history for this message
Tres Seaver (tseaver) wrote :

Adding comments is now protected by the 'comment' permission, which is granted
as part of karl.security.policy.GUEST_PERMS (e.g., to KarlStaff in a public community).

Changed in karl3:
status: New → Fix Committed
Changed in karl3:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.