Closed Bug 527040 Opened 15 years ago Closed 15 years ago

duplicates.cgi does not use the central bug visibility mechanism

Categories

(Bugzilla :: Reporting/Charting, defect)

defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 514970

People

(Reporter: gerv, Unassigned)

Details

Bugzilla->user->visible_bugs is the central place for checking bug visibility.
duplicates.cgi does not use it. It probably should. 

It does create a Search object and use the SQL returned with the explicit purpose of getting security checking. One way of fixing bugs like this might be to "move" the positioning of the interface on the Search object so that it returns a set of Bug objects rather than an SQL string. Then, we could centralize any post-search visibility filtering inside Search.pm.

No patch for this one yet, sorry.

Gerv
This one will be handled by bug 514970.
Status: NEW → RESOLVED
Closed: 15 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.