And so it will deny access to files it totally has no business with.

Support from Acquia helps fund testing for Drupal Acquia logo

Comments

chx’s picture

And so is the patch :D

chx’s picture

quicksketch’s picture

Title: webform_file_download query does not check for file » webform_file_download query does not check that file is owned by Webform
Priority: Critical » Major

Finally committed.

quicksketch’s picture

Status: Needs review » Fixed
ygerasimov’s picture

Status: Fixed » Reviewed & tested by the community

Sorry but I can't see patch #1 committed. Please also be aware that patch is formed based on different path sites/all/modules/webform/webform.module and not module's root.

Manually applying patch solves the issue.

quicksketch’s picture

Status: Reviewed & tested by the community » Fixed

I just hadn't pushed yet. It's there now.

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.