You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Is is intentional that anonymous users can change the size and position of notices and that these are stored in Plone persistently? I'd assume that normal security applies and only people with access to a notice can also change its position/size. Now an anonymouse user can 'destroy' a noticeboard by accident or on purpose.
The text was updated successfully, but these errors were encountered:
Oh oh, I remember now, I think we did this on purpose. @pbauer help!
IIRC there were two design constraints we had in mind while developing this board:
If you can see the board, you can see all messages.
If you can see the board, you can shuffle around notes.
I am not perfectly sure about the second point but the implementation I added now is not good, because it means, only if I edit a note, I can shuffle it around. It should probably have a different permission.
Is is intentional that anonymous users can change the size and position of notices and that these are stored in Plone persistently? I'd assume that normal security applies and only people with access to a notice can also change its position/size. Now an anonymouse user can 'destroy' a noticeboard by accident or on purpose.
The text was updated successfully, but these errors were encountered: