Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

anonymous users can change notice position/size #6

Open
fredvd opened this issue Oct 28, 2014 · 3 comments
Open

anonymous users can change notice position/size #6

fredvd opened this issue Oct 28, 2014 · 3 comments
Labels

Comments

@fredvd
Copy link
Member

fredvd commented Oct 28, 2014

Is is intentional that anonymous users can change the size and position of notices and that these are stored in Plone persistently? I'd assume that normal security applies and only people with access to a notice can also change its position/size. Now an anonymouse user can 'destroy' a noticeboard by accident or on purpose.

@do3cc do3cc added bug and removed question labels Oct 30, 2014
@do3cc
Copy link
Member

do3cc commented Oct 30, 2014

No, it is not intentional, it is an oversight.

do3cc added a commit that referenced this issue Oct 30, 2014
@do3cc do3cc closed this as completed in a839c9d Oct 30, 2014
@do3cc
Copy link
Member

do3cc commented Oct 30, 2014

Thank you @fredvd

@do3cc do3cc reopened this Oct 30, 2014
@do3cc
Copy link
Member

do3cc commented Oct 30, 2014

Oh oh, I remember now, I think we did this on purpose. @pbauer help!

IIRC there were two design constraints we had in mind while developing this board:

  1. If you can see the board, you can see all messages.
  2. If you can see the board, you can shuffle around notes.

I am not perfectly sure about the second point but the implementation I added now is not good, because it means, only if I edit a note, I can shuffle it around. It should probably have a different permission.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants