Ticket #4292 (reopened defect)
ROADMAP_VIEW / MILESTONE_VIEW privilege
| Reported by: | dave@… | Owned by: | jonas |
|---|---|---|---|
| Priority: | normal | Milestone: | 0.13 |
| Component: | general | Version: | 0.10.2 |
| Severity: | major | Keywords: | |
| Cc: | dave@… |
Description
roadmap.py is checking for ROADMAP_VIEW, which will only work as long as one keeps the ROADMAP_VIEW permission for anonymous that's set up by db_default.py. Once you delete that, nobody without WIKI_ADMIN privileges can look at the roadmap, because you can create MILESTONE_VIEW privs to your hearts content but they'll be ignored.
Attachments
Change History
Note: See
TracTickets for help on using
tickets.


