Skip to content

fix authorize#3099

Merged
raycarrick-ed merged 1 commit intomasterfrom
plan_policy_fix
Jan 28, 2022
Merged

fix authorize#3099
raycarrick-ed merged 1 commit intomasterfrom
plan_policy_fix

Conversation

@raycarrick-ed
Copy link
Contributor

Fixes security issue with plan policy.

Changes proposed in this PR:

authorize on index method in contributors controller had no effect in essence allowing anyone access to any plan. See ticket above for an example. This change requires the :show? policy to be satisfied.

@raycarrick-ed raycarrick-ed merged commit 0a32936 into master Jan 28, 2022
@raycarrick-ed raycarrick-ed deleted the plan_policy_fix branch January 28, 2022 12:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant