[Koha-bugs] [Bug 7550] Self checkout: limit display of patron image to logged-in patron

bugzilla-daemon at bugs.koha-community.org bugzilla-daemon at bugs.koha-community.org
Wed Apr 19 22:32:07 CEST 2017


https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=7550

--- Comment #17 from Jonathan Druart <jonathan.druart at bugs.koha-community.org> ---
I do not understand how your approach can protect the image in any way if
SelfCheckoutByLogin="barcode".

Hit /cgi-bin/koha/sco/sco-main.pl
Guess a cardnumber
=> You see the image

Both approaches have the same problem, that's why I suggest to add a warning on
the about page.

The only difference is that the second approach uses Koha::Token that it
already used at different places.

-- 
You are receiving this mail because:
You are watching all bug changes.


More information about the Koha-bugs mailing list