[Koha-bugs] [Bug 17479] REST API: Save information on owner access

bugzilla-daemon at bugs.koha-community.org bugzilla-daemon at bugs.koha-community.org
Fri Mar 10 10:03:59 CET 2017


https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=17479

Marcel de Rooy <m.de.rooy at rijksmuseum.nl> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |m.de.rooy at rijksmuseum.nl

--- Comment #5 from Marcel de Rooy <m.de.rooy at rijksmuseum.nl> ---
Just a dumb [hypothetical] question, since I am not that deep into Mojolicious
etc.
You only set the flag; you do not clear the flag.
How do you make sure that setting this owner flag is not misused/abused later
on? Is it possible that it is still on thru persistence?
I could imagine that you would clear this flag in the else branch of the
haspermission if?

-- 
You are receiving this mail because:
You are watching all bug changes.


More information about the Koha-bugs mailing list