Uploaded image for project: 'Apache Roller'
  1. Apache Roller
  2. ROL-1983

Only expose AJAX User List Servlet to admin users

    XMLWordPrintableJSON

Details

    • Task
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 5.0.3, 5.1.0
    • 5.0.4, 5.1.0
    • User Management
    • None

    Description

      For some reason the Roller user list is presently implemented via a servlet, allowing the list of blog users and email addresses to be publicly accessible for those accessing the URL. Goal here is to shut off the servlet and use a traditional Struts/JPA method of listing the users on the page, perhaps similar to our blog entry listing screen.

      UPDATE: there's nothing wrong with using a Servlet for this AJAX operation, but we should only expose the Servlet to those who are logged into Roller as site admins.

      Attachments

        Activity

          People

            gmazza Glen Mazza
            gmazza Glen Mazza
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: