Details

    • Type: Task Task
    • Status: Resolved Resolved
    • Priority: Major Major
    • Resolution: Obsolete
    • Affects Version/s: Current Version
    • Fix Version/s: None
    • Component/s: OIOIOI
    • Labels:
      None

      Description

      Students are to be allowed to ask for teacher permissions, so that they can run contests while taking part in others. We have to make sure that giving these permissions are safe enough to be given to untrusted users.

        Issue Links

          Activity

          Michał Łazowik made changes -
          Field Original Value New Value
          Summary Make teacher privileges secure Check if teacher privileges secure
          Description Teacher privileges aren't necessarily secure. Make them secure.
          While doing this task keep in mind that students will have access to teacher accounts - they should see only what they have to.
          Students are to be allowed to ask for teacher permissions, so that they can run contests while taking part in others. We have to make sure that giving these permissions are safe enough to be given to untrusted users.
          Michał Łazowik made changes -
          Summary Check if teacher privileges secure Check if teacher privileges are secure
          Hide
          Michał Łazowik added a comment - - edited
          They are not. See blocking tasks.
          Show
          Michał Łazowik added a comment - - edited They are not. See blocking tasks.
          Michał Łazowik made changes -
          Summary Check if teacher privileges are secure Make teacher permissions secure
          Michał Łazowik made changes -
          Status New [ 10000 ] Open [ 1 ]
          Michał Łazowik made changes -
          Status Open [ 1 ] Resolved [ 5 ]
          Assignee Szymon Acedański [ accek ]
          Resolution Fixed [ 1 ]
          Michał Łazowik made changes -
          Resolution Fixed [ 1 ]
          Status Resolved [ 5 ] Reopened [ 4 ]
          Assignee Szymon Acedański [ accek ] Michał Łazowik [ mlazowik ]
          Michał Łazowik made changes -
          Link This issue is blocked by SIO-1813 [ SIO-1813 ]
          Michał Łazowik made changes -
          Link This issue is blocked by SIO-1814 [ SIO-1814 ]
          Michał Łazowik made changes -
          Link This issue is blocked by SIO-1790 [ SIO-1790 ]
          Michał Łazowik made changes -
          Link This issue is blocked by SIO-1791 [ SIO-1791 ]
          Michał Łazowik made changes -
          Link This issue is blocked by SIO-1798 [ SIO-1798 ]
          Hide
          Gerrit Gerrit added a comment -
          Change I6925252509f9e79caa7e81c2f3c24b2001e1ee82, patchset 1
          https://gerrit.sio2project.mimuw.edu.pl/2563

          SIO-1780 Unmark dashboard message as safe html

          We plan to give teacher permissions to regular users, we cannot trust that they
          will not use this for XSS.

          We might want to enable markdown in that field.

          Change-Id: I6925252509f9e79caa7e81c2f3c24b2001e1ee82
          Show
          Gerrit Gerrit added a comment - Change I6925252509f9e79caa7e81c2f3c24b2001e1ee82, patchset 1 https://gerrit.sio2project.mimuw.edu.pl/2563 SIO-1780 Unmark dashboard message as safe html We plan to give teacher permissions to regular users, we cannot trust that they will not use this for XSS. We might want to enable markdown in that field. Change-Id: I6925252509f9e79caa7e81c2f3c24b2001e1ee82
          Michał Łazowik made changes -
          Status Reopened [ 4 ] In Progress [ 3 ]
          Szymon Acedański made changes -
          Assignee Michał Łazowik [ mlazowik ]
          Fix Version/s TAG 2015/16 Sprint 1 [ 12400 ]
          Szymon Acedański made changes -
          Labels T3 tag1
          Szymon Acedański made changes -
          Labels tag1
          Hide
          Szymon Acedański added a comment -
          This issue has been automatically closed as Obsolete due to no activity for 365 days.

          Feel free to reopen it or create a new one if it's still relevant.
          Show
          Szymon Acedański added a comment - This issue has been automatically closed as Obsolete due to no activity for 365 days. Feel free to reopen it or create a new one if it's still relevant.
          Szymon Acedański made changes -
          Status In Progress [ 3 ] Resolved [ 5 ]
          Assignee Szymon Acedański [ accek ]
          Resolution Obsolete [ 7 ]
          Transition Time In Source Status Execution Times Last Executer Last Execution Date
          New New Open Open
          6d 23h 47m 1 Michał Łazowik 2016-03-30 17:02
          Open Open Resolved Resolved
          21d 8h 41m 1 Michał Łazowik 2016-04-21 1:44
          Resolved Resolved Reopened Reopened
          21d 9h 46m 1 Michał Łazowik 2016-05-12 11:30
          Reopened Reopened In Progress In Progress
          2d 4h 35m 1 Michał Łazowik 2016-05-14 16:06
          In Progress In Progress Resolved Resolved
          1444d 22m 1 Szymon Acedański 2020-04-27 16:28

            People

            • Assignee:
              Szymon Acedański
              Reporter:
              Mateusz Śmiech
            • Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: