Uploaded image for project: 'Gateway'
  1. Gateway
  2. GTWY-4791

URL hacking allows users to edit brokered datasets

XMLWordPrintable

      While you can't get to some pages through the UI (e.g . brokered datasets don't allow getting to upload or responsible party pages)
      you can hack there and get to the page:
      /dataset/cordex.raw.NAM-22i.mon.RegCM4.HadGEM2-ES.rcp85.tasmax/editfiles.html

      AC: The user should be prevented from accessing edit for brokered datasets.

              cgrant Christy Grant
              cgrant Christy Grant
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: