[pkg-horde] Bug#858950: Bug#858950: Turba does not obey restrictions defined in Horde permission system

Mathieu Parent math.parent at gmail.com
Wed May 3 06:01:40 UTC 2017


Control: tag -1 + upstream fixed-upstream
Control: fixed -1 4.2.6-1

2017-03-29 1:02 GMT+02:00 Leonardo Bruno <leobruno at gmail.com>:
> Package: php-horde-turba
> Version: 4.2.2-3
> Severity: normal
> Tags: patch
>
> Scenario: Suppose you have a 'localldap' contacts source which is read-only.
> Also suppose you have set for this source only 'Read' and 'Show' permissions
> to 'All Authenticated Users', using the Horde permission system, available
> under 'Adminsitration' menu.
>
> Symptoms: Turba will show 'New contact > in localldap' menu option and will
> also allow one to fill out the new contact form for this source. However,
> when the user click the 'Add' button, Turba will show this error message
> 'There was an error adding the new contact. Contact your system
> administrator for further help.' in that red square box.
>
> There seems to be a typo in line 431 of
> /usr/share/horde/turba/lib/Turba.php; The argument of the 'create' function
> is '$source' but it should be '$sourceId', as I could confirm by inspecting
> the Turba.php file in the package available in Debian stretch repositories,
> which ships the version 4.2.18-1 of Turba.
>
> Attached is a minimal patch that solves the problem.

Thanks.

This looks like upstream:
https://github.com/horde/horde/commit/91ce536ce03a18eb9d30b6f9a104664081cd8159
https://github.com/horde/horde/commit/cbc8d0720c73a44b16ba16dd765c6a8312aad7de

Fixed in 4.2.3 (and so, not in stretch).

Regards

-- 
Mathieu Parent



More information about the pkg-horde-hackers mailing list