Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Any user can access proposal's pages representing the "create a proposal" steps #8390

Merged
merged 1 commit into from
Oct 14, 2021

Conversation

roxanaopr
Copy link
Contributor

@roxanaopr roxanaopr commented Oct 11, 2021

Any user can access the links from "create a new proposal" steps (compare. complete, preview, publish).

  1. With account A login
  2. Create an idea
  3. Stop at any of the mentioned steps
  4. Save the link for this step
  5. Access link via incognito (logged in with another account or not logged in)

Observed: Any guest or user has access to the copied links

🎩 What? Why?

Please describe your pull request.

📌 Related Issues

#8386

Testing

Describe the best way to test or validate your PR.

📋 Checklist

🚨 Please review the guidelines for contributing to this repository.

  • CONSIDER adding a unit test if your PR resolves an issue.
  • ✔️ DO check open PR's to avoid duplicates.
  • ✔️ DO keep pull requests small so they can be easily reviewed.
  • ✔️ DO build locally before pushing.
  • ✔️ DO make sure tests pass.
  • ✔️ DO make sure any new changes are documented in docs/.
  • ✔️ DO add and modify seeds if necessary.
  • ✔️ DO add CHANGELOG upgrade notes if required.
  • ✔️ DO add to GraphQL API if there are new public fields.
  • ✔️ DO add link to MetaDecidim if it's a new feature.
  • AVOID breaking the continuous integration build.
  • AVOID making significant changes to the overall architecture.

📷 Screenshots

Please add screenshots of the changes you're proposing
Description

♥️ Thank you!

@roxanaopr roxanaopr force-pushed the fix/proposal-creation-steps branch 2 times, most recently from 687866a to 9d83591 Compare October 11, 2021 14:21
@roxanaopr roxanaopr changed the title Any user can access proposals in "Compare", "Preview" and "Publish" page steps Any user can access proposals in "Compare", "Complete", "Preview" and "Publish" page steps Oct 11, 2021
@roxanaopr roxanaopr changed the title Any user can access proposals in "Compare", "Complete", "Preview" and "Publish" page steps Any user can access proposal's pages representing the "create a proposal" steps Oct 11, 2021
@roxanaopr roxanaopr force-pushed the fix/proposal-creation-steps branch 2 times, most recently from 763deec to e4c680d Compare October 12, 2021 15:04
@leio10 leio10 added team: security module: proposals type: fix PRs that implement a fix for a bug labels Oct 13, 2021
@roxanaopr roxanaopr force-pushed the fix/proposal-creation-steps branch 2 times, most recently from 63c07b6 to ea77ef5 Compare October 13, 2021 11:31
@roxanaopr roxanaopr force-pushed the fix/proposal-creation-steps branch from ea77ef5 to dd795f4 Compare October 13, 2021 12:34
Copy link
Contributor

@leio10 leio10 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@leio10 leio10 merged commit b3b2efd into decidim:develop Oct 14, 2021
@leio10
Copy link
Contributor

leio10 commented Oct 14, 2021

Thanks for taking care of this @roxanaopr! ❤️
Please, can you backport it to the 0.25 branch?

roxanaopr added a commit to tremend-cofe/decidim that referenced this pull request Oct 14, 2021
leio10 pushed a commit that referenced this pull request Oct 15, 2021
@alecslupu alecslupu added this to the 0.26.0 milestone Jul 14, 2023
@alecslupu alecslupu deleted the fix/proposal-creation-steps branch October 31, 2024 05:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants