跳至內容
選單
此問題已被標幟
3878 瀏覽次數

This is a serious security concern, defining group access rights on menu items is not enough to restrict access to actions

How do you protect against this ? someone could just try action ids one by one until they find an existing action that gives him/her access to potentially private information.

I restricted access to a window action to a specific group, but I was still able to see it with a user that doesn't belong to that group.

Is this a bug? or am I missing something?

頭像
捨棄
相關帖文 回覆 瀏覽次數 活動
1
10月 23
8458
0
3月 15
3696
1
3月 15
5107
0
3月 25
820
2
10月 24
1774