Closed (fixed)
Project:
Content Construction Kit (CCK)
Version:
6.x-2.x-dev
Component:
General
Priority:
Normal
Category:
Bug report
Assigned:
Reporter:
Created:
3 Aug 2009 at 16:29 UTC
Updated:
17 Aug 2009 at 21:00 UTC
Jump to comment: Most recent file
Comments
Comment #1
amitaibuThis is actually a CCK issue.
(p.s. please add diff to CCK component).
Comment #2
amitaibuAnd here's the patch.
Comment #3
markus_petrux commentedCuriously enough I reported this issue to the Drupal security team a week or so ago. They concluded it could be resolved in the CCK queue and no additional action would be needed. In the meantime, I was discussing with yched and KarenS what to do next...
@Amitaibu: your patch is not correct as CCK provides a function for this: content_access().
Attached is the patch that will be committed to CVS, and I guess it will happen asap.
Comment #4
amitaibuThanks, indeed, only after submitting the patch I realized it might be a security issue. Anyway, thanks for the re-roll.
Comment #5
markus_petrux commentedCommitted to CVS (branches CCK2 and CCK3).
Soon to be released as CCK 2.5.