Opened 9 years ago

Closed 8 years ago

#7344 closed (duplicate)

Plus sign still available even if add rights are not granted

Reported by: mrtot Owned by: nobody
Component: contrib.admin Version: master
Severity: Keywords: newforms-admin, foreign key, admin
Cc: Triage Stage: Accepted
Has patch: no Needs documentation: no
Needs tests: no Patch needs improvement: no
Easy pickings: UI/UX:

Description (last modified by Ramiro Morales)

When you have a model like this:

class Player
  #...

class PlayerImage
  player = model.ForeignKey(Player)

And you login with a user that has full rights on PlayerImage but only modify rights on Player he still sees the plus sign next to the drop down list "Player" in the change PlayerImage menu.

Change History (3)

comment:1 Changed 8 years ago by Jeff Anderson

Keywords: newforms-admin added; plus sign removed
Triage Stage: UnreviewedAccepted

I've confirmed that this is indeed a bug in the oldforms-admin, as will as in newforms-admin.

On clicking on the "plus sign", you get a nice "permission denied" message, so it isn't a security problem. It is more of an aesthetic issue than anything.

comment:2 Changed 8 years ago by Ramiro Morales

Description: modified (diff)

comment:3 Changed 8 years ago by anonymous

Resolution: duplicate
Status: newclosed

dupe of #1035

Note: See TracTickets for help on using tickets.
Back to Top