Skip to content

Fix(Core): use item-scoped access check on escalation routes - #490

Merged
Rom1-B merged 4 commits into
mainfrom
some_fix
Aug 28, 2026
Merged

Fix(Core): use item-scoped access check on escalation routes#490
Rom1-B merged 4 commits into
mainfrom
some_fix

Conversation

@stonebuzz

Copy link
Copy Markdown
Contributor

Checklist before requesting a review

Please delete options that are not relevant.

  • I have performed a self-review of my code.
  • I have added tests (when available) that prove my fix is effective or that my feature works.
  • I have updated the CHANGELOG with a short functional description of the fix or new feature.
  • This change requires a documentation update.

Description

use item-scoped access check on escalation routes

Screenshots (if appropriate):

@stonebuzz
stonebuzz requested a review from Rom1-B August 28, 2026 07:22
@stonebuzz stonebuzz self-assigned this Aug 28, 2026

@Rom1-B Rom1-B left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you add a test asserting a user with only ASSIGN (not UPDATE) can reach these routes, and one with only UPDATE (not ASSIGN) cannot?

Comment thread front/climb_group.php Outdated
Comment thread front/ticket.form.php Outdated
stonebuzz and others added 3 commits August 28, 2026 10:00
Co-authored-by: Romain B. <8530352+Rom1-B@users.noreply.github.com>
Co-authored-by: Romain B. <8530352+Rom1-B@users.noreply.github.com>
@stonebuzz
stonebuzz requested a review from Rom1-B August 28, 2026 12:46
@Rom1-B
Rom1-B merged commit 7d52bd6 into main Aug 28, 2026
3 checks passed
@Rom1-B
Rom1-B deleted the some_fix branch August 28, 2026 13:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants