Opened 7 years ago

Closed 7 years ago

#7344 closed (duplicate)

Plus sign still available even if add rights are not granted

Reported by: mrtot Owned by: nobody
Component: contrib.admin Version: master
Severity: Keywords: newforms-admin, foreign key, admin
Cc: Triage Stage: Accepted
Has patch: no Needs documentation: no
Needs tests: no Patch needs improvement: no
Easy pickings: UI/UX:

Description (last modified by ramiro)

When you have a model like this:

class Player
  #...

class PlayerImage
  player = model.ForeignKey(Player)

And you login with a user that has full rights on PlayerImage but only modify rights on Player he still sees the plus sign next to the drop down list "Player" in the change PlayerImage menu.

Change History (3)

comment:1 Changed 7 years ago by programmerq

  • Keywords newforms-admin added; plus sign removed
  • Needs documentation unset
  • Needs tests unset
  • Patch needs improvement unset
  • Triage Stage changed from Unreviewed to Accepted

I've confirmed that this is indeed a bug in the oldforms-admin, as will as in newforms-admin.

On clicking on the "plus sign", you get a nice "permission denied" message, so it isn't a security problem. It is more of an aesthetic issue than anything.

comment:2 Changed 7 years ago by ramiro

  • Description modified (diff)

comment:3 Changed 7 years ago by anonymous

  • Resolution set to duplicate
  • Status changed from new to closed

dupe of #1035

Note: See TracTickets for help on using tickets.
Back to Top