openstudyroom icon indicating copy to clipboard operation
openstudyroom copied to clipboard

anonymous users should not be able to add available events

Open climu opened this issue 4 years ago • 4 comments

@LucasBertrand I assign you :)

climu avatar Jun 04 '21 08:06 climu

Wait, how you actually do that from the client ? I also verified, the view check user's permission.

LucasBertrand avatar Jun 05 '21 09:06 LucasBertrand

You can always pass something in the context. I use to load a different js file for anonymous since lot of client logic goes away. Your call.

climu avatar Jun 05 '21 10:06 climu

I mean, anonymous users cannot add available events at the current state, or tell me how you do that :) I have some checks in my js functions and on the server, the request user pass the authenticated check

Make a selection on the calendar does nothing when your anonymous (I will desactivate the mouse event)

LucasBertrand avatar Jun 08 '21 12:06 LucasBertrand

The event are not stored on the database. It's just client side issue. To reproduce:

  1. Logout OSR website and go to https://openstudyroom.org/calendar/
  2. Click the week view
  3. Click and drag on the calendar

This will create such an event and that's not the expected behaviour: image

climu avatar Jun 08 '21 16:06 climu