mirror of
https://gh.wpcy.net/https://github.com/discourse/discourse.git
synced 2026-05-26 21:18:34 +08:00
A non obvious issue in data explorer is that it can return sideloaded data (topic/user/post) ensure side loaded data runs through security rules for account viewing it. Can easily be bypassed by amending the query so it will have minimal impact. |
||
|---|---|---|
| .. | ||
| group_spec.rb | ||
| query_controller_spec.rb | ||