Skip to content

security fix for plan policy#3084

Closed
raycarrick-ed wants to merge 2 commits intomasterfrom
plan_policy_bug
Closed

security fix for plan policy#3084
raycarrick-ed wants to merge 2 commits intomasterfrom
plan_policy_bug

Conversation

@raycarrick-ed
Copy link
Contributor

Fixes security issue with plan policy.

Changes proposed in this PR:

  • authorize on index method in contributors controller had no effect in essence allowing anyone access to any plan. See ticket above for an example. This change requires the :show? policy to be satisfied.

@raycarrick-ed raycarrick-ed requested a review from briri January 6, 2022 17:57
@raycarrick-ed
Copy link
Contributor Author

Latest commit was trying to sort out rubocop issues. Will continue with the rest later.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant