[development] Re: Drupal.org upgrade

Dries Buytaert dries.buytaert at gmail.com
Mon Feb 13 07:46:49 UTC 2006


On 13 Feb 2006, at 08:34, Robert Douglass wrote:
>> I don't think anyone has been looking into this.  It's a show-  
>> stopping issue so any help is appreciated.  Likely a bug in CVS HEAD.
>>> security issue: I'm able to outline pages
>>> http://drupal.org/node/48790
>> Unlike users on drupal.org, users on scratch.drupal.org have the   
>> 'maintain books' permission ... This is the result of a decision  
>> that  was made recently on the documentation mailing list.  The  
>> goal was to  invite more people to make changes/edits to the  
>> handbook.  Being able  to outline book pages doesn't sound like a  
>> good idea though.
>
> This sounds like a good case for splitting the outlining into a  
> separate permission?

Probably.  We need to investigate the code though.  Maybe 'maintain  
books' is no longer the best permission name.

--
Dries Buytaert  ::  http://www.buytaert.net/



More information about the development mailing list