Uploaded image for project: 'Medici'
  1. Medici
  2. MMDB-1681

Block editing/deletion of comment by non-author on server-side.

XMLWordPrintableJSON

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Major Major
    • None
    • 2.0
    • Web application
    • None
    • Right now the editing/deletion of comment by non-author is only blocked on client-side JS, and can be bypassed by accessing the API functions in api.Comments directly. This must be blocked by a server-side check.

            mfelarca Mario Felarca
            csophocleous Constantinos Sophocleous
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: