Repository navigation
GH Issue #1444: Improve permission checking on secure message replies - #8128
labkey-adam wants to merge 5 commits into
Conversation
|
For manual testing, attempt to POST to this URL, changing the Looks like this action requires a non-JSON post, which the |
|
Manual test findings: Note: These findings are all around the message board APIs (createThread.api and updateThread.api). Since users can call these APIs directly, perhaps they should follow the same rules as the UI. Test findings 1 and 2 below show places where the API behaves differently from the UI. Test finding 3 is a side effect where an API edit unexpectedly changes the saved notify list. Setup
Test findings
Expected: The API explicitly rejects Jim's reply as a reply parent, the same way the UI does (404, "Could not find message"). 2) API replies drop notify-list members who temporarily can't read the thread, permanently and without saying so
Expected: The UI and API handle a member who can't read the thread the same way. The API doesn't remove someone without saying so.
Folder: OpenBoard
Expected: Editing only the body leaves the original message's notify list unchanged (Jim, Creed). |
Rationale
Prevent users who aren't on a secure thread's member list from replying to it, and stop API replies and edits from clearing a thread's member list. See GH Issue 1444.
Changes