Closed (fixed)
Project:
Drupal core
Version:
7.x-dev
Component:
other
Priority:
Critical
Category:
Bug report
Assigned:
Unassigned
Issue tags:
Reporter:
Created:
12 Aug 2010 at 18:38 UTC
Updated:
3 Jan 2014 at 01:42 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #1
grendzy commented.
Comment #2
gábor hojtsyHere is the D7 port of the "Comment unpublishing bypass" (1 of 4 issues).
Comment #3
gábor hojtsyHere is a patch for the "File download access bypass" issue which I can only assume helps. Upload module is no more, but file field is there.
Comment #4
gábor hojtsyI assume Heine has ports for the OpenID patches, so not working on those now.
Comment #5
scor commentedWas the actions XSS issue fixed elsewhere?
Comment #6
gábor hojtsy@scor: I don't think so. Will ping Heine about patches he might have.
Comment #7
heine commentedI've posted the OpenID assertion verification patch in #886982: Incomplete verification of assertions.
Comment #8
heine commentedThe actions on D7 are incorrectly double escaped and should be in a separate issue.
Comment #9
heine commentedActions has changed quite a bit and is now at #887102: Trigger & Action escaping issues.
Comment #10
gábor hojtsyOk then we only need to deal with the small fixes from #2 and #3 in here. Any review feedback? Should I merge them into one patch?
Comment #11
grendzy commentedI think a combined patch would be easier - the project workflow doesn't support multiple patches per issue very well.
Comment #12
scor commentedmerged patches.
Comment #13
scor commentedwith documentation. we could probably bake in a test for the file issue as well.
Comment #14
grendzy commentedI tested both issues; this patch works as expected.
Comment moderation issue:
- before: comment/1/edit works on unpublished comments
- after: 403 forbidden
file issue:
before: system/files/TeSt.JpG displays the file
after: 404 page
Comment #15
dries commentedCommitted to CVS HEAD. Thanks.