? Pending

User tests: Successful: Unsuccessful:

avatar ggppdk
ggppdk
2 Sep 2017

Same fix as fix that had been applied here in the past to the article controller :

https://github.com/joomla/joomla-cms/blob/staging/administrator/components/com_content/controllers/article.php#L80-L89

https://github.com/joomla/joomla-cms/blob/staging/administrator/components/com_content/controllers/article.php#L112

Same as PRs
#17838
#17840

This is minor security issue,
if user than has "edit" on fields component, is denied editing configuration of a specific field ,
then user will still be able to edit the field's configuration

Summary of Changes

Testing Instructions

Expected result

Actual result

Documentation Changes Required

avatar joomla-cms-bot joomla-cms-bot - change - 2 Sep 2017
Category Administration com_fields
avatar ggppdk ggppdk - open - 2 Sep 2017
avatar ggppdk ggppdk - change - 2 Sep 2017
Status New Pending
avatar ggppdk ggppdk - change - 2 Sep 2017
The description was changed
avatar ggppdk ggppdk - edited - 2 Sep 2017
avatar ggppdk ggppdk - change - 2 Sep 2017
The description was changed
avatar ggppdk ggppdk - edited - 2 Sep 2017
avatar ggppdk ggppdk - change - 2 Sep 2017
The description was changed
avatar ggppdk ggppdk - edited - 2 Sep 2017
avatar sanderpotjer sanderpotjer - test_item - 3 Sep 2017 - Tested successfully
avatar sanderpotjer
sanderpotjer - comment - 3 Sep 2017

I have tested this item successfully on b2167f5


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/17839.

avatar Sieger66 Sieger66 - test_item - 12 Sep 2017 - Tested successfully
avatar Sieger66
Sieger66 - comment - 12 Sep 2017

I have tested this item successfully on b2167f5


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/17839.

avatar franz-wohlkoenig franz-wohlkoenig - change - 12 Sep 2017
Status Pending Ready to Commit
avatar franz-wohlkoenig
franz-wohlkoenig - comment - 12 Sep 2017

RTC after two successful tests.

avatar mbabker mbabker - close - 25 Sep 2017
avatar mbabker mbabker - merge - 25 Sep 2017
avatar mbabker mbabker - change - 25 Sep 2017
Status Ready to Commit Fixed in Code Base
Closed_Date 0000-00-00 00:00:00 2017-09-25 11:42:23
Closed_By mbabker
Labels Added: ?

Add a Comment

Login with GitHub to post a comment