Download & Extend

User should not be able set a parent for non-subscribed group

Project:Subgroups for Organic groups
Version:5.x-3.0-dev
Component:Code
Category:bug report
Priority:critical
Assigned:ezra-g
Status:closed (fixed)

Issue Summary

Example:
I have 2 groups A and B
User subscribed to grouped A
User adds a sub-group, but in Add form he's allowed to set the parent as group B.

This is an access violation, as some groups are moderated and don't allow edit them.

In my opinion, groups that user is not subscribed, shouldn't appear in the parents list.

Comments

#1

Version:5.x-2.0» 5.x-3.0-dev
Priority:normal» critical
Assigned to:Anonymous» ezra-g

This will be fixed shortly.

#2

Status:active» fixed

Fixed in 5.x-3.0 with commit # 103133. thanks to Amitaibu for pointing this out.

Attached is a patch detailing the changes I made.

AttachmentSize
190837-security.patch 12.61 KB

#3

Status:fixed» closed (fixed)

Automatically closed -- issue fixed for two weeks with no activity.

nobody click here