Skip to content

GitLab

  • Menu
Projects Groups Snippets
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
  • Sign in / Register
  • erp5 erp5
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Merge requests 141
    • Merge requests 141
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Jobs
  • Commits
Collapse sidebar
  • nexedi
  • erp5erp5
  • Merge requests
  • !1035

Open
Created Jan 24, 2020 by Jérome Perrin@jeromeOwner
  • Report abuse
Report abuse

WIP: Prevent Zope publication of workflow methods

  • Overview 6
  • Commits 2
  • Pipelines 2
  • Changes 4

All workflow methods became published a few years ago, maybe when we updated CMF or Zope. This properly implements in ERP5 the protection of workflow methods, it should not be able to pass a workflow method transition from an HTTP request, unless this transition wraps a method that is publishable.

WIP: At this point, this MR just "repair ERP5", the next step can be to remove guards on workflow methods on all default workflows, like it was done here for validation_workflow.

Assignee
Assign to
Reviewer
Request review from
Time tracking
Source branch: fix/workflow_method_security
GitLab Nexedi Edition | About GitLab | About Nexedi | 沪ICP备2021021310号-2 | 沪ICP备2021021310号-7