Homec4science

Policy - make ManiphestTaskQuery verify project visibility first thing

Authored by Bob Trahan <btrahan@phacility.com> on Feb 3 2015, 22:53.

Description

Policy - make ManiphestTaskQuery verify project visibility first thing

Summary: Fixes T7094 (last of many revisions). Its important to do this filtering ASAP so that users can't deduce the identify of an unknown / invisible project.

Test Plan: executed a query for tasks in project foo using user bar. using user foo, lock user bar out of project foo. reissued the query and saw "no data" as well as "restricted project" in the project typeahead.

Reviewers: epriestley

Reviewed By: epriestley

Subscribers: Korvin, epriestley

Maniphest Tasks: T7094

Differential Revision: https://secure.phabricator.com/D11660

Details

Committed
Bob Trahan <btrahan@phacility.com>Feb 3 2015, 22:53
Pushed
aubortJan 31 2017, 17:16
Parents
rPH137b0ebc53a1: Phabot / Conduit - stop using deprecated conduit api paste.info
Branches
Unknown
Tags
Unknown

Event Timeline

Bob Trahan <btrahan@phacility.com> committed rPHda1531f219d0: Policy - make ManiphestTaskQuery verify project visibility first thing (authored by Bob Trahan <btrahan@phacility.com>).Feb 3 2015, 22:53