HomePhorge

Policy - make ManiphestTaskQuery verify project visibility first thing

Description

Policy - make ManiphestTaskQuery verify project visibility first thing

Summary: Fixes T7094 (last of many revisions). Its important to do this filtering ASAP so that users can't deduce the identify of an unknown / invisible project.

Test Plan: executed a query for tasks in project foo using user bar. using user foo, lock user bar out of project foo. reissued the query and saw "no data" as well as "restricted project" in the project typeahead.

Reviewers: epriestley

Reviewed By: epriestley

Subscribers: Korvin, epriestley

Maniphest Tasks: T7094

Differential Revision: https://secure.phabricator.com/D11660

Details

Provenance
Bob TrahanAuthored on Feb 3 2015, 1:53 PM
themackabuPushed on Mar 25 2025, 8:07 PM
Parents
rP137b0ebc53a1: Phabot / Conduit - stop using deprecated conduit api paste.info
Branches
Unknown
Tags
Unknown

Event Timeline