group file/folders are not locked when a personal page includes them in artefacts and is submitted

Bug #1036035 reported by Hugh Davenport
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Mahara
Confirmed
Wishlist
Unassigned

Bug Description

Use case:
user creates a group, adds a folder to group files area, puts some files in that folder
user then creates a personal page, with a folder artefact pointing to that group folder
user then submits that page to another group
while teacher is reviewing submitted page, the user could change the contents of that folder, and/or delete items

The same probably happens with institution files and site files areas.

These file/folders should be locked, and things like bug #1032009 and bug #1031592 also be applied.

Changed in mahara:
milestone: none → 1.6.0
security vulnerability: yes → no
visibility: private → public
Changed in mahara:
importance: Medium → Wishlist
milestone: 1.6.0 → none
Revision history for this message
Kristina Hoeppner (kris-hoeppner) wrote :

See also https://bugs.launchpad.net/mahara/+bug/644169 for locking pretty much everything on a page.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.