Alan Guo Xiang Tan
3d581ce159
SECURITY: Category group permissions leaked to normal users.
...
After this commit, category group permissions can only be seen by users
that are allowed to manage a category. In the past, we inadvertently
included a category's group permissions settings in `CategoriesController#show`
and `CategoriesController#find_by_slug` endpoints for normal users when
those settings are only a concern to users that can manage a category.
2022-04-08 11:04:59 +02:00
..
2022-01-14 09:33:15 +10:00
2022-01-18 08:26:27 -06:00
2021-12-02 15:12:25 +00:00
2021-08-10 15:07:40 +01:00
2021-09-21 08:45:47 +10:00
2021-12-01 16:10:40 +00:00
2022-04-08 11:04:59 +02:00
2021-06-22 13:00:04 -05:00
2021-06-29 14:43:38 -05:00
2021-01-27 10:29:24 -06:00
2021-09-14 15:18:01 +03:00
2021-07-26 12:19:30 +10:00
2021-08-30 10:37:53 +05:30
2020-08-28 11:46:53 -07:00
2021-12-17 14:03:35 +01:00
2022-01-08 23:39:46 +01:00
2021-12-22 11:09:43 -06:00
2021-05-21 11:43:47 +10:00
2022-01-13 10:42:48 +02:00
2021-12-20 12:59:10 -06:00
2022-01-20 10:54:38 +00:00
2020-11-25 10:53:05 +11:00
2021-05-21 11:43:47 +10:00
2020-11-03 12:38:54 +00:00
2021-12-15 11:41:14 -06:00
2021-05-21 11:43:47 +10:00
2022-01-17 18:05:14 -03:00
2021-10-07 15:50:14 +01:00
2020-11-06 10:33:19 +10:00
2022-01-13 16:02:07 -05:00
2021-06-15 12:35:45 -03:00
2021-11-30 12:55:25 +03:00
2021-06-21 11:06:58 +08:00
2021-11-18 09:21:12 +08:00
2022-01-26 10:39:58 +02:00
2021-01-25 11:23:36 +01:00
2021-08-17 14:05:51 -04:00
2021-12-21 20:51:18 +01:00
2021-06-21 11:06:58 +08:00
2021-06-30 11:25:05 +08:00
2021-04-27 14:05:45 +03:00
2021-08-02 12:41:41 +08:00
2021-05-21 11:43:47 +10:00
2022-01-11 01:51:57 +01:00
2021-07-07 18:57:42 +02:00
2021-11-18 09:17:23 +10:00
2021-12-08 21:46:54 +04:00
2020-09-29 10:57:48 +01:00
2021-06-02 20:29:47 +02:00
2021-12-22 11:09:43 -06:00
2022-01-27 10:12:37 -05:00
2021-11-25 09:34:39 +02:00