Opened 12 years ago

Closed 12 years ago

#7344 closed (duplicate)

Plus sign still available even if add rights are not granted

Reported by: mrtot Owned by: nobody
Component: contrib.admin Version: master
Severity: Keywords: newforms-admin, foreign key, admin
Cc: Triage Stage: Accepted
Has patch: no Needs documentation: no
Needs tests: no Patch needs improvement: no
Easy pickings: no UI/UX: no

Description (last modified by Ramiro Morales)

When you have a model like this:

class Player

class PlayerImage
  player = model.ForeignKey(Player)

And you login with a user that has full rights on PlayerImage but only modify rights on Player he still sees the plus sign next to the drop down list "Player" in the change PlayerImage menu.

Change History (3)

comment:1 Changed 12 years ago by Jeff Anderson

Keywords: newforms-admin added; plus sign removed
Triage Stage: UnreviewedAccepted

I've confirmed that this is indeed a bug in the oldforms-admin, as will as in newforms-admin.

On clicking on the "plus sign", you get a nice "permission denied" message, so it isn't a security problem. It is more of an aesthetic issue than anything.

comment:2 Changed 12 years ago by Ramiro Morales

Description: modified (diff)

comment:3 Changed 12 years ago by anonymous

Resolution: duplicate
Status: newclosed

dupe of #1035

Note: See TracTickets for help on using tickets.
Back to Top