Menu

#565 The submission creation process doesn't validate title types

v1.0 (example)
closed-fixed
None
5
2015-12-13
2015-02-20
Ahasuerus
No

The submission creation process doesn't validate title types. This enables editors who bypass the standard data entry forms (e.g. when using Google Translate) to submit non-standard title types like "NIEUWE". If approved, this type of submission will result in an empty title type because our MySQL settings are very permissive and default to empty string if an invalid enumerated value is filed.

Discussion

  • Ahasuerus

    Ahasuerus - 2015-02-20
    • Description has changed:

    Diff:

    --- old
    +++ new
    @@ -1 +1 @@
    -The submission creation process doesn't validate title types. This lets editors who bypass the standard data entry forms the ability to submit non-standard title types like "NIEUWE". It's not a major risk because an attempt to approve such a submission would result in an error and nothing bad would be filed into the database, but it's still a nuisance.
    +The submission creation process doesn't validate title types. This lets editors who bypass the standard data entry forms the ability to submit non-standard title types like "NIEUWE". If approved, this type of submission will result in an empty title type because our MySQL settings are very permissive and default to empty string if an invalid enumerated value is filed.
    
     
  • Ahasuerus

    Ahasuerus - 2015-12-12
    • Description has changed:

    Diff:

    --- old
    +++ new
    @@ -1 +1 @@
    -The submission creation process doesn't validate title types. This lets editors who bypass the standard data entry forms the ability to submit non-standard title types like "NIEUWE". If approved, this type of submission will result in an empty title type because our MySQL settings are very permissive and default to empty string if an invalid enumerated value is filed.
    +The submission creation process doesn't validate title types. This enables editors who bypass the standard data entry forms (e.g. when using Google Translate) to submit non-standard title types like "NIEUWE". If approved, this type of submission will result in an empty title type because our MySQL settings are very permissive and default to empty string if an invalid enumerated value is filed.
    
    • assigned_to: Ahasuerus
     
  • Ahasuerus

    Ahasuerus - 2015-12-13

    Fixed in:

    common/pubClass.py 1.32
    common/titleClass.py 1.30
    

    Installed in r2015-247 on 2015-12-13.

     
  • Ahasuerus

    Ahasuerus - 2015-12-13
     
  • Ahasuerus

    Ahasuerus - 2015-12-13
    • status: open --> closed-fixed
     
  • Ahasuerus

    Ahasuerus - 2015-12-13

    Closing.

     

Anonymous
Anonymous

Add attachments
Cancel





MongoDB Logo MongoDB