Custom Query (22 matches)
Results (19 - 21 of 22)
Ticket | Resolution | Summary | Owner | Reporter |
---|---|---|---|---|
#22 | fixed | Project admin page editable by logged in user, not just admins | support@… | tim.te.beek@… |
Description |
Any logged in user can administrate any project, by altering the below URL in a predictable manner: https://trac.nbic.nl/admin/ProjectAdmin.php?mode=editproject&project=sandbox Currently the only requirement is that the user is logged in, not whether or not the user is an administrator for the project. This constitutes a mayor security project for every current Trac project. |
|||
#1 | invalid | ticket! | somebody | evert.lammerts@… |
Description |
ticktick |
|||
#27 | fixed | Test ticket for ticket show details | eelco@… | eelco@… |
Description |
This is a test ticket to see changes to ticket_show_details option in trac.ini |
Note: See TracQuery
for help on using queries.