The SIO2 project
  1. The SIO2 project
  2. SIO-1704

Custom ModelAdmin class doesn't check related objects permissions

    Details

    • Type: Bug Bug
    • Status: Resolved Resolved
    • Priority: Major Major
    • Resolution: Obsolete
    • Affects Version/s: Current Version
    • Fix Version/s: None
    • Component/s: OIOIOI
    • Labels:
      None

      Description

      OIOIOI's ModelAdmin overrides delete_view() implementation. It's very similar to that of Django, but it only checks delete permissions of the object being deleted. If a delete cascade occurs there can be an object that is protected or shouldn't be deleted anyway.

        Activity

        Adam Paszke made changes -
        Field Original Value New Value
        Assignee Adam Paszke [ apaszke ]
        Szymon Acedański made changes -
        TAG Developer Adam Paszke [ apaszke ]
        Szymon Acedański made changes -
        TAG Developer Adam Paszke [ apaszke ]
        Szymon Acedański made changes -
        Assignee Adam Paszke [ apaszke ]
        Artur Puzio made changes -
        Assignee Artur Puzio [ ert ]
        Artur Puzio made changes -
        Assignee Artur Puzio [ ert ]
        Szymon Acedański made changes -
        Status New [ 10000 ] Resolved [ 5 ]
        Assignee Szymon Acedański [ accek ]
        Resolution Obsolete [ 7 ]

          People

          • Assignee:
            Szymon Acedański
            Reporter:
            Adam Paszke
          • Votes:
            1 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: