]> git.vanrenterghem.biz Git - git.ikiwiki.info.git/commitdiff
describe unexpected situation where a logged-in user can delete other comments
authorjmtd <jmtd@web>
Thu, 30 Sep 2021 13:59:32 +0000 (09:59 -0400)
committeradmin <admin@branchable.com>
Thu, 30 Sep 2021 13:59:32 +0000 (09:59 -0400)
doc/bugs/logged_in_users_can_remove_any_comments.mdwn [new file with mode: 0644]

diff --git a/doc/bugs/logged_in_users_can_remove_any_comments.mdwn b/doc/bugs/logged_in_users_can_remove_any_comments.mdwn
new file mode 100644 (file)
index 0000000..e4bd44e
--- /dev/null
@@ -0,0 +1,6 @@
+[ the precise circumstances around which this can happen are still being nailed down ]
+
+[[plugins/remove]] says:
+> Users can only remove things that they are allowed to edit or upload.
+
+This permits a logged-in user to remove comments by other users, which might be unexpected. *&mdash; [[Jon]], 2021-09-30*