<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
  <title>aC forum: [Fixed] Security problem: view projects without having rights to see them</title>
  <link>http://www.activecollab.com/forums/topic/187/</link>
  <description>Recent posts on topic: [Fixed] Security problem: view projects without having rights to see them</description>
  <dc:language>en-us</dc:language>
  <pubDate>Mon, 13 Feb 2012 07:44:47 CST</pubDate>
  
  <item>
    <link>http://www.activecollab.com/forums/post/7852/#post7852</link>
    <guid>http://www.activecollab.com/forums/post/7852/#post7852</guid>
    <title>Post #11 by [user deleted]</title>
    <dc:creator>[user deleted]</dc:creator>
    <description><![CDATA[<p>Sorry if I'm reviving a dead horse here, but I did test the active_project=xxx issue with 0.7.1 recently, and I can view other projects though not assigned to the user.<br />
<br />
Wondering if I'm doing something wrong? </p>]]></description>
    <pubDate>Wed, 30 May 2007 20:46:28 CDT</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/6021/#post6021</link>
    <guid>http://www.activecollab.com/forums/post/6021/#post6021</guid>
    <title>Post #10 by Ilija Studen</title>
    <dc:creator>Ilija Studen</dc:creator>
    <description><![CDATA[<p>If you are wondering if this problem is fixed than just to point out: it has been <b>fixed</b> long time ago.</p>]]></description>
    <pubDate>Fri, 19 Jan 2007 07:43:20 CST</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/2560/#post2560</link>
    <guid>http://www.activecollab.com/forums/post/2560/#post2560</guid>
    <title>Post #9 by Ilija Studen</title>
    <dc:creator>Ilija Studen</dc:creator>
    <description><![CDATA[<p>I'm afraid that things are a bit more complex than that - there are several changes in ProjectController plus some in other files and because this one was commited as part of a set of changes I can' isolate them.</p>]]></description>
    <pubDate>Tue, 29 Aug 2006 00:41:20 CDT</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/2553/#post2553</link>
    <guid>http://www.activecollab.com/forums/post/2553/#post2553</guid>
    <title>Post #8 by [user deleted]</title>
    <dc:creator>[user deleted]</dc:creator>
    <description><![CDATA[<p>Can this problem be solved with updating some files or do we have to wait until a next version? Thanks!</p>]]></description>
    <pubDate>Mon, 28 Aug 2006 16:34:06 CDT</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/2287/#post2287</link>
    <guid>http://www.activecollab.com/forums/post/2287/#post2287</guid>
    <title>Post #7 by Ilija Studen</title>
    <dc:creator>Ilija Studen</dc:creator>
    <description><![CDATA[<p>Fixed in SVN R32...</p>]]></description>
    <pubDate>Sun, 20 Aug 2006 03:22:10 CDT</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/1026/#post1026</link>
    <guid>http://www.activecollab.com/forums/post/1026/#post1026</guid>
    <title>Post #6 by Ilija Studen</title>
    <dc:creator>Ilija Studen</dc:creator>
    <description><![CDATA[<p>Yes, aC have pretty strong permissions system but I missed to add checks on some pages. I think I'll create more flexible permissions system for 1.0, just to make a good foundation for future versions where will have extensible permissions for plugins and all the stuff we put in.</p>]]></description>
    <pubDate>Sun, 16 Jul 2006 15:45:02 CDT</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/1024/#post1024</link>
    <guid>http://www.activecollab.com/forums/post/1024/#post1024</guid>
    <title>Post #5 by SimonK</title>
    <dc:creator>SimonK</dc:creator>
    <description><![CDATA[<p>Nice, thanks. I wasn't able to test it with cookies/sessions cleared (see first reply) since my servers have been down since yesterday morning (yeah, the DreamHost fileserver thingie).<br />
<br />
Quite funny by the way, I noticed my (test) client could not post new messages or anything: those links were hidden. So you did not overlook it completely... ;)</p>]]></description>
    <pubDate>Sun, 16 Jul 2006 15:41:39 CDT</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/1003/#post1003</link>
    <guid>http://www.activecollab.com/forums/post/1003/#post1003</guid>
    <title>Post #4 by Ilija Studen</title>
    <dc:creator>Ilija Studen</dc:creator>
    <description><![CDATA[<p><div class="postQuote"><blockquote><div class="quoteAuthor">SimonK:</div>I was actually surprised that this wasn't brought up yet, am I the only one playing with URL's all the time? :P It's probably something you overlooked. Other than this I think it's pretty stable, though I hope you're planning to make upgrading a bit easier. :) Great job, this tool wil make communicating a lot more easier.</blockquote></div><br />
I overlooked it :( Permissions are really important in this kind of system so this will be fixed ASAP.<br />
<br />
<div class="postQuote"><blockquote><div class="quoteAuthor">SimonK:</div>Oh, by the way, the only thing your great app lacks is AJAX. It would make the use even easier than it already is, especially since I find my self clicking a lot of links (and thus refreshing quite often). But don't rush it, take your time to develop a good and stable app.</blockquote></div><br />
XHR will use aC API to send async requests. So, API first, then AJAX.</p>]]></description>
    <pubDate>Sun, 16 Jul 2006 10:53:22 CDT</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/971/#post971</link>
    <guid>http://www.activecollab.com/forums/post/971/#post971</guid>
    <title>Post #3 by [user deleted]</title>
    <dc:creator>[user deleted]</dc:creator>
    <description><![CDATA[<p>I toyed with it and found the same issue. As a client, I changed the last part of the URL from <br />
<br />
active_project=2<br />
to<br />
active_project=1<br />
<br />
and had access to a project 1, where I was not a member. I could not download a PDF file or read messages from the link in the overview log, but I could view messages using the tab links.</p>]]></description>
    <pubDate>Sat, 15 Jul 2006 16:15:25 CDT</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/952/#post952</link>
    <guid>http://www.activecollab.com/forums/post/952/#post952</guid>
    <title>Post #2 by [user deleted]</title>
    <dc:creator>[user deleted]</dc:creator>
    <description><![CDATA[<p>Did you clear your cookie and reset your session or was it just a URL change that induced the behavior?</p>]]></description>
    <pubDate>Fri, 14 Jul 2006 17:45:47 CDT</pubDate>
  </item>
</channel>
</rss>
