Closed (fixed)
Project:
Rep[lacement]Tags
Version:
5.x-1.8
Component:
Javascript / AJAX
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
17 May 2007 at 16:39 UTC
Updated:
31 May 2007 at 17:01 UTC
With a small client-side modification to the AJAX code (in reptag_helper.js) it is possible to add/edit/delete tags of other users. The ajax callback does not bypass the access restrictions of the Drupal site nor does it allow the user to list other users tags. However I just committed a patch which adds a check to ensure that a user can only access its own tags.
Comments
Comment #1
profix898 commentedComment #2
(not verified) commented