Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Worst fix ever. #407

Merged
merged 4 commits into from
May 22, 2023
Merged

Worst fix ever. #407

merged 4 commits into from
May 22, 2023

Conversation

TacticalTechJay
Copy link
Collaborator

@TacticalTechJay TacticalTechJay commented May 17, 2023

This PR should be P1~P0 as it fixes an issue where any user can delete another user's file. All they have to do is guess the numbered id of a file. This fix will only allow admins or superAdmins to delete other user's files.

@github-actions github-actions bot added this to the 3.7.1 milestone May 17, 2023
@diced diced merged commit 60d7b22 into diced:trunk May 22, 2023
SinonCute pushed a commit to SinonCute/zipline that referenced this pull request Jun 30, 2023
* fix: Worst, but minimally working, fix so other users do not delete each other's files.

* fix: include previous fix for PATCH

---------

Co-authored-by: dicedtomato <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants