Skip to content
This repository was archived by the owner on Jan 26, 2021. It is now read-only.

Added fix to disable unauthorized access by volunteers #449

Merged
merged 1 commit into from
Mar 7, 2017
Merged

Added fix to disable unauthorized access by volunteers #449

merged 1 commit into from
Mar 7, 2017

Conversation

Yureien
Copy link
Contributor

@Yureien Yureien commented Feb 11, 2017

This PR fixes the closed, wrong PR #430 and fixes issue #326 .

In addition to the links mentioned in the issue, I've also fixed these urls -

  1. /volunteer/edit/ - Previously could be accessed by anyone
  2. /volunteer/add_hours/ - Previously could be accessed by anyone
  3. /volunteer/edit_hours/ - Previously could be accessed by anyone
  4. /shift/cancel/ - Previously showed an Http 403 page, fixed to show same error page as other ones.

Here is the screenshot -
screenshot from 2017-01-13 23-10-43

@coveralls
Copy link

Coverage Status

Coverage decreased (-0.03%) to 91.72% when pulling dac9219 on InfernoCoder:VOLUNTEER_URL into 880a3c8 on systers:develop.

@smarshy
Copy link
Contributor

smarshy commented Mar 7, 2017

@InfernoCoder Thanks for the work!

@smarshy smarshy merged commit 9b7aea8 into anitab-org:develop Mar 7, 2017
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants