Skip to content

Check for user permissions before firing ajax actions #19

@mathetos

Description

@mathetos

Reported by @TimothyBJacobs

The Ajax action is restricted to logged-in users, but I don’t think that is sufficient. A logged-in user, perhaps a commenter, could make a request to either download the file or generate a remote viewing URL.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions