Skip to content
This repository was archived by the owner on Jul 24, 2020. It is now read-only.
This repository was archived by the owner on Jul 24, 2020. It is now read-only.

Sensitive information on Equipment Model pages is available to the public #1749

Closed
@orenyk

Description

@orenyk

One of our users just brought to our attention that when he is looking at an equipment model, he can see the list of items and who has them checked out, as well as our checkin/checkout procedures. I used the “view as” to check as both a Patron and as a Guest (as well as opening a browser where I’m not logged in) and they can indeed see those things. No wonder another person looked at me like I was a lying jerk when he asked me to tell him who had something out and I told him no!

This should be fixed ASAP.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions