HomePhorge

Policy - lock down loadCommit() from DiffusionRequest objects

Description

Policy - lock down loadCommit() from DiffusionRequest objects

Summary: Ref T7094. The class DiffusionRequest has other public methods which use getUser() in an unguarded way. Code inspection of the call sites for loadCommit() also leads me to believe the $user is properly set.

Test Plan: clicked around diffusion a bunch and everything seemed to work okay. (happy to test any particular esoteric endpoints that come to mind)

Reviewers: epriestley

Reviewed By: epriestley

Subscribers: Korvin, epriestley

Maniphest Tasks: T7094

Differential Revision: https://secure.phabricator.com/D11585

Details

Provenance
Bob TrahanAuthored on Feb 1 2015, 9:33 AM
themackabuPushed on Mar 25 2025, 8:07 PM
Parents
rP93e6a9b3caad: Allow subscriptions to cost amounts other than one dollar and twenty three cents
Branches
Unknown
Tags
Unknown

Event Timeline