Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

gpnf-disable-sessions.php: Fixed an issue where non privileged users are not able to edit or delete entries. #874

Closed
wants to merge 1 commit into from

Conversation

barthc
Copy link
Contributor

@barthc barthc commented Aug 21, 2024

Context

⛑️ Ticket(s): https://secure.helpscout.net/conversation/2677531768/69897

Summary

When the GPNF disable session snippet is active, non-privileged users can not edit or delete entries. This PR will fix the issue.

Copy link

Warnings
⚠️ When ready, don't forget to request reviews on this pull request from your fellow wizards.

Generated by 🚫 dangerJS against e516ddf

@spivurno
Copy link
Contributor

@barthc Closing this PR in favor of #877. This approach felt a little clunky by requiring the user to specify both a parent and child form ID in the code and presented an opportunity for malicious users to populate existing child entries into a Nested Form field for which they should have no access.

@spivurno spivurno closed this Aug 27, 2024
@spivurno spivurno deleted the barth/fix/69897-edit-delete-entry branch August 27, 2024 00:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

2 participants