Skip to content

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
    • Help
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
erp5
erp5
  • Project
    • Project
    • Details
    • Activity
    • Releases
    • Cycle Analytics
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Charts
  • Merge Requests 115
    • Merge Requests 115
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
    • Charts
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Charts
  • Jobs
  • Commits
  • nexedi
  • erp5erp5
  • Merge Requests
  • !1035

Open
Opened Jan 24, 2020 by Jérome Perrin@jerome
  • Report abuse
Report abuse

WIP: Prevent Zope publication of workflow methods

All workflow methods became published a few years ago, maybe when we updated CMF or Zope. This properly implements in ERP5 the protection of workflow methods, it should not be able to pass a workflow method transition from an HTTP request, unless this transition wraps a method that is publishable.

WIP: At this point, this MR just "repair ERP5", the next step can be to remove guards on workflow methods on all default workflows, like it was done here for validation_workflow.

Check out, review, and merge locally

Step 1. Fetch and check out the branch for this merge request

git fetch origin
git checkout -b fix/workflow_method_security origin/fix/workflow_method_security

Step 2. Review the changes locally

Step 3. Merge the branch and fix any conflicts that come up

git fetch origin
git checkout origin/master
git merge --no-ff fix/workflow_method_security

Step 4. Push the result of the merge to GitLab

git push origin master

Note that pushing to GitLab requires write access to this repository.

Tip: You can also checkout merge requests locally by following these guidelines.

  • Discussion 5
  • Commits 3
  • Pipelines 1
  • Changes 7
Assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
0
Labels
None
Assign labels
  • View project labels
Reference: nexedi/erp5!1035
GitLab Nexedi Edition | About GitLab | About Nexedi | 沪ICP备14008524号