MantisBT

View Issue Details Jump to Notes ] Wiki ] Related Changesets ] Issue History ] Print ]
IDProjectCategoryView StatusDate SubmittedLast Update
0008843mantisbttime trackingpublic2008-01-31 14:202008-08-11 09:41
ReporterLoki 
Assigned Todaryn 
PrioritynormalSeverityminorReproducibilityalways
StatusclosedResolutionfixed 
PlatformWindowsOSServerOS Version2000
Product Version1.1.1 
Target VersionFixed in Version1.2.0a2 
Summary0008843: Ignores tracking_reporting_threshold
Description# access level required to run reports
    $g_time_tracking_reporting_threshold = MANAGER;

Time Tracking ignores this setting
Steps To ReproduceLogin as a developer with the default threshold of Manager and you can go to the Billing link and run reports.
TagsNo tags attached.
Attached Filesdiff file icon billing_access_check.diff [^] (1,248 bytes) 2008-02-01 07:25 [Show Content]
diff file icon billing_access_check2.diff [^] (1,108 bytes) 2008-02-04 05:43 [Show Content]

- Relationships

-  Notes
User avatar (0016907)
kynx (reporter)
2008-02-01 07:27

Attached diff that removes 'Billing' link from menu and prevents access to billing page if user does not have correct threshold
User avatar (0016920)
Loki (reporter)
2008-02-01 21:39

I applied the diffs but still have access below threshold level.
User avatar (0016925)
GregorK (reporter)
2008-02-03 05:01

Works perfect here...
User avatar (0016933)
kynx (reporter)
2008-02-04 05:35

My mistake - I was checking the viewing threshold, not the reporting threshold. Will attach updated patch.
User avatar (0016947)
daudo (reporter)
2008-02-04 17:21

IMO this is a major security flaw, because it unveils potential secret data to anyone.

Without the patch applied, even anonymous people not even have logged in can see and use the "billing" link and see at least the ID, title and resolver of any resolved bug.
User avatar (0016953)
kynx (reporter)
2008-02-05 05:02

+1. If you're using time tracking, you'll want to have a look at 0008357 and 0008849, which also deal with the time showing to people it shouldn't.

The time tracking stuff is a great addition. It would be good to see these issues on the roadmap for the next release.
User avatar (0016957)
daudo (reporter)
2008-02-05 06:22

excellent, thanks for the two additional hints :-)
User avatar (0017637)
daryn (developer)
2008-04-21 10:40

Applied modified patch. ( Changes to codebase caused initial patch to fail ).

- Related Changesets
MantisBT: master bb78e8a1
Timestamp: 2008-04-21 14:30:21
Author: daryn
Details ] Diff ]
Permissions checks for timetracking.

git-svn-id: http://mantisbt.svn.sourceforge.net/svnroot/mantisbt/trunk@5184 [^] /?p=mantisbt.git;a=object;h=f5dc347c-c33d-0410-90a0-b07cc1902cb9
mod - billing_page.php Diff ] File ]
mod - core/html_api.php Diff ] File ]
MantisBT: master-1.1.x 1c203913
Timestamp: 2008-04-21 14:30:21
Author: daryn
Details ] Diff ]
Fix 0008843, 10050: Permissions checks for timetracking.

<span class="signoff">Signed-off-by: John Reese <jreese@leetcode.net></span>
mod - billing_page.php Diff ] File ]
mod - core/html_api.php Diff ] File ]

- Issue History
Date Modified Username Field Change
2008-01-31 14:20 Loki New Issue
2008-02-01 07:25 kynx File Added: billing_access_check.diff
2008-02-01 07:27 kynx Note Added: 0016907
2008-02-01 21:39 Loki Note Added: 0016920
2008-02-02 01:19 daryn Assigned To => daryn
2008-02-02 01:19 daryn Status new => acknowledged
2008-02-03 05:01 GregorK Note Added: 0016925
2008-02-04 05:35 kynx Note Added: 0016933
2008-02-04 05:43 kynx File Added: billing_access_check2.diff
2008-02-04 17:21 daudo Note Added: 0016947
2008-02-05 05:02 kynx Note Added: 0016953
2008-02-05 06:22 daudo Note Added: 0016957
2008-04-21 10:40 daryn Status acknowledged => resolved
2008-04-21 10:40 daryn Fixed in Version => 1.2.0a2
2008-04-21 10:40 daryn Resolution open => fixed
2008-04-21 10:40 daryn Note Added: 0017637
2008-08-11 09:41 giallu Status resolved => closed
2009-01-14 10:46 jreese Changeset attached master bb78e8a1 =>
2009-01-14 11:00 daryn Changeset attached master-1.1.x 1c203913 =>


MantisBT 1.2.17 [^]
Copyright © 2000 - 2014 MantisBT Team
Time: 0.0977 seconds.
memory usage: 3,081 KB
Powered by Mantis Bugtracker