Code

Opened 6 years ago

Closed 6 years ago

#7344 closed (duplicate)

Plus sign still available even if add rights are not granted

Reported by: mrtot Owned by: nobody
Component: contrib.admin Version: master
Severity: Keywords: newforms-admin, foreign key, admin
Cc: Triage Stage: Accepted
Has patch: no Needs documentation: no
Needs tests: no Patch needs improvement: no
Easy pickings: UI/UX:

Description (last modified by ramiro)

When you have a model like this:

class Player
  #...

class PlayerImage
  player = model.ForeignKey(Player)

And you login with a user that has full rights on PlayerImage but only modify rights on Player he still sees the plus sign next to the drop down list "Player" in the change PlayerImage menu.

Attachments (0)

Change History (3)

comment:1 Changed 6 years ago by programmerq

  • Keywords newforms-admin, key, admin added; key,admin, plus sign removed
  • Needs documentation unset
  • Needs tests unset
  • Patch needs improvement unset
  • Triage Stage changed from Unreviewed to Accepted

I've confirmed that this is indeed a bug in the oldforms-admin, as will as in newforms-admin.

On clicking on the "plus sign", you get a nice "permission denied" message, so it isn't a security problem. It is more of an aesthetic issue than anything.

comment:2 Changed 6 years ago by ramiro

  • Description modified (diff)

comment:3 Changed 6 years ago by anonymous

  • Resolution set to duplicate
  • Status changed from new to closed

dupe of #1035

Add Comment

Modify Ticket

Change Properties
<Author field>
Action
as closed
as The resolution will be set. Next status will be 'closed'
The resolution will be deleted. Next status will be 'new'
Author


E-mail address and user name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.