##// END OF EJS Templates
security: make sure the admin of repo can only delete comments which are from the same repo....
security: make sure the admin of repo can only delete comments which are from the same repo. - fixes IDOR issue - protects against other people comment deletion by repo admins.

File last commit:

r1:854a839a default
r1818:1ced1b24 default
Show More
public-access.rst
12 lines | 402 B | text/x-rst | RstLexer

Public Access

By default |RCM| allows users to read all public |repos|. User permissions and |repo| access can be configured explicitly, and those permissions will override any default settings. The default settings can be found under the following section:

  • :menuselection:`Admin --> Permissions --> Object`
  • :menuselection:`Admin --> Permissions --> Global`