Closed (won't fix)
Project:
Vote Up/Down
Version:
5.x-1.x-dev
Component:
Code
Priority:
Critical
Category:
Bug report
Assigned:
Reporter:
Created:
9 Jan 2008 at 11:49 UTC
Updated:
11 Jun 2010 at 08:45 UTC
Jump to comment: Most recent file
Comments
Comment #1
Christefano-oldaccount commented+1
I can confirm this. Perhaps the bug could have been disclosed more discretely?
Comment #2
nicholasthompsonDiscretely - maybe... Although I haven't given any links to effected sites.
I was just quite concerned and thought I should post something up to make sure other users are aware of it.
I did try to find him on IRC first.
Comment #3
frjo commentedPlease test this patch and see it it helps and don't mess up any other stuff.
Comment #4
nicholasthompsonHaven't had a chance to actually test it yet (been in a meeting all day) but a visual/mental "compile" appears to be fine. The workflow looks sound and secure - assuming FALSE until proven to be TRUE to a very good idea.
I cant see that breaking anything - but I'll test it for you just to be sure.
Thanks.
Nick
Comment #5
drupalnewbiehaha commentedI can't see any sec problem, but it does caused an error message when I give a vote directly (http://site/vote_up_down/node/1/1/1). Applied the patch works fine, the error was gone and can't reproduce, the patch code looks good, too.
Comment #6
marvil07 commentedPlease take a look to the update on the project page, now
5.xis not-really-maintained.