We should check whether the user has access to view userpoints or not.

CommentFileSizeAuthor
author_pane-userpoints-permission.patch658 bytesquotesbro

Comments

michelle’s picture

Bah, I guess they still haven't implemented #941158: Add permissioned wrapper to public point retrieval API eh? I don't have a D6 dev environment right now and this will need to go thru all the security rigmarole, too, so will probably be a bit. But it doesn't look like the Userpoints maintainer is going to do the sensible thing so I guess I don't have much choice.

Michelle

michelle’s picture

Version: 6.x-2.x-dev » 7.x-2.x-dev

I'm going to bump this to D7 because it's also an issue there and AP D7 isn't a full release and we really shouldn't have an issue for a security issue in a stable release. I'll try to find some time to backport it, though. I'm not supporting D6 anymore but I can't ignore a security issue unless I'm willing to mark the release as unsupported, which will needlessly freak out 20K people who are using it just fine because of a problem that no one has complained about in over year. :(

Michelle

Scyther’s picture

Issue tags: +7.x-2.x-beta-blocker

Will take a look at this as soon I has time for it!

@Michelle - I have a D6 dev site with AP on, so I can take a look at fix for D6 if you like.

michelle’s picture

Oh, that would be awesome! The only D6 site I still have is a live site that hasn't been touched in a _very_ long time and I'd be afraid it would totally fall to pieces if I messed with it. LOL!

Feel free to just go ahead and commit to D6 as well, for this or any other thing that comes up that you feel so inclined to take on. I just really don't have time for Author Pane, especially since Artesian won't be using it.

Thanks,

Michelle

Scyther’s picture

Scyther’s picture

Status: Needs review » Fixed
michelle’s picture

Thank you! One less stress for me. :)

Michelle

quotesbro’s picture

Thank you!

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.