Skip to content
#

journal

Here are 455 public repositories matching this topic...

mauromsl
mauromsl commented Jun 9, 2020

Describe the bug
From the do_revision view, authors can delete previously uploaded files. The files themselves are not deleted, but rather unlinked from the article object.
There are no permissions checked against the file before it gets "deleted" so the author could tweak the posted file_id and potentially "delete" any file in the article

Janeway version
v1.3.8

**To Reproduce

Improve this page

Add a description, image, and links to the journal topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the journal topic, visit your repo's landing page and select "manage topics."

Learn more

You can’t perform that action at this time.