Warning: Can't synchronize with repository "(default)" (/home/git/ome.git does not appear to be a Git repository.). Look in the Trac log for more information.
Notice: In order to edit this ticket you need to be either: a Product Owner, The owner or the reporter of the ticket, or, in case of a Task not yet assigned, a team_member"

Task #2910 (closed)

Opened 11 years ago

Closed 11 years ago

Last modified 11 years ago

Bug: Table service does not respect write permissions

Reported by: jamoore Owned by: jamoore
Priority: major Milestone: OMERO-Beta4.2.1
Component: Security Version: n.a.
Keywords: n.a. Cc:
Resources: n.a. Referenced By: n.a.
References: n.a. Remaining Time: 0.0d
Sprint: 2010-09-30 (17)

Description

Before returning a table service, the Tables API checks for read-permissions, but insufficient checks are made of the write permissions especially post-group permissions (#1434).

See #2909

Change History (8)

comment:1 Changed 11 years ago by jmoore

  • Remaining Time set to 1

comment:2 Changed 11 years ago by jmoore

(In [8114]) Partially saving files after modification in OmeroTables (See #2908, #2909, #2910)

Though this calls saves on tables.close(), based on the group settings the service may not have sufficient permissions (even as root) to do so.

comment:3 Changed 11 years ago by cxallan

  • Priority changed from critical to major

comment:4 Changed 11 years ago by cxallan

  • Sprint set to 2010-09-09 (16)

comment:5 Changed 11 years ago by jburel

  • Sprint changed from 2010-09-09 (16) to 2010-09-30 (17)

comment:6 Changed 11 years ago by jmoore

  • Owner set to jmoore
  • Status changed from new to assigned

comment:7 Changed 11 years ago by jmoore

  • Remaining Time changed from 1 to 0
  • Resolution set to fixed
  • Status changed from assigned to closed

(In [8305]) Added Table.assert_write to all mutators (Fix #2910)

comment:8 Changed 11 years ago by jmoore

(In [8339]) Fixing OmeroTables tests after API usage change (See #2910)

Note: See TracTickets for help on using tickets. You may also have a look at Agilo extensions to the ticket.

1.3.13-PRO © 2008-2011 Agilo Software all rights reserved (this page was served in: 0.69122 sec.)

We're Hiring!