[Koha-bugs] [Bug 29503] GET /patrons should use Koha::Patrons->search_limited

bugzilla-daemon at bugs.koha-community.org bugzilla-daemon at bugs.koha-community.org
Thu Jan 6 00:53:27 CET 2022


https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=29503

--- Comment #10 from Tomás Cohen Arazi <tomascohen at gmail.com> ---
(In reply to Tomás Cohen Arazi from comment #7)
> I'm lowering the severity because, as bug 29509 highlights, we actually
> require all _borrowers_ permissions to use the route (iincluding
> view_borrower_infos_from_any_libraries).
> 
> But those permissions are too high for using the routes on the API, and this
> bug (and bug 29506) will prevent leakages when time comes.

I wrote this and forgot to change the 'Product'. Sorry for that

-- 
You are receiving this mail because:
You are watching all bug changes.


More information about the Koha-bugs mailing list