[drupal-devel] [bug] node revisions should only be viewable by admins

killes drupal-devel at drupal.org
Wed Aug 31 13:48:42 UTC 2005


Issue status update for 
http://drupal.org/node/30098
Post a follow up: 
http://drupal.org/project/comments/add/30098

 Project:      Drupal
 Version:      cvs
 Component:    node system
 Category:     bug reports
 Priority:     normal
 Assigned to:  Anonymous
 Reported by:  killes at www.drop.org
 Updated by:   killes at www.drop.org
 Status:       patch (code needs review)
 Attachment:   http://drupal.org/files/issues/node_rev.patch (1.27 KB)

With or without the revisions patch, every user who can access content
can access old revisions. I think this is a bug because why would you
need to see old revisions if you cannot change them or make them the
current revision?


The attached patch fixes this and lets only users with "administer
nodes" permission see old revs as you need this permission to change
revisiosn to be the current one.


One might make a case for introducing new "view revisions" and "set
revisions" perms. You woud need those if you wanted to mimic a wiki
with Drupal.




killes at www.drop.org




More information about the drupal-devel mailing list