[sakai2-tcc] inadvertently deleting sites bug

Steve Swinsburg steve.swinsburg at gmail.com
Tue Feb 12 13:42:01 PST 2013


It's not just special sites that can be deleted in this way, it affects all sites. So rather than a band aid, a full fix would be best if its doable. 

Cheers
Steve

Gesendent von meinem iPhone

On 13/02/2013, at 2:18, Charles Severance <csev at umich.edu> wrote:

> I agree - ugly bug.  The bad news is that as Aaron says, it requires a bit of digging.  The good news is that after
> 
> https://jira.sakaiproject.org/browse/SAK-20834  (r94951) it is actually *possible* to pull this kind of info out of state and move it to the URL.
> 
> I did a similar bit of work in the Mail Archive tool (yes far a far simpler) - but once I dug in - it was not too hard to switch from state to URL parameters.
> 
> I agree with the suggestion of sanity checks on certain sites that should not be deleted - and we may want to do that anyways.  I am just pointing out that we *can* fix this the right way as well if we like.
> 
> Assignments would be another candidate.
> 
> /Chuck
> 
> On Feb 12, 2013, at 8:15 AM, Aaron Zeckoski wrote:
> 
>> Ugly bug. We can put in a hack solution to not allow the special sites
>> to be removed (i.e. the !siteId ones, but that would be for all cases
>> and not just this one) or a real solution which is to rewrite this
>> code to not use the session state. That probably means digging into
>> SiteAction and some very tricky bits of code.
>> 
>> -AZ
>> 
>> 
>> On Tue, Feb 12, 2013 at 8:05 AM, Steve Swinsburg
>> <steve.swinsburg at gmail.com> wrote:
>>> Hi all,
>>> 
>>> This issue was raised a few weeks ago where an admin user could delete sites inadvertently, including the gateway and admin workspace, simply by using two tabs in the admin sites tool
>>> https://jira.sakaiproject.org/browse/SAK-23143
>>> 
>>> Can we discuss  a possible solution? Note I haven't set this as a security issue since its only admin users that can do this.
>>> 
>>> cheers,
>>> Steve
>>> _______________________________________________
>>> sakai2-tcc mailing list
>>> sakai2-tcc at collab.sakaiproject.org
>>> http://collab.sakaiproject.org/mailman/listinfo/sakai2-tcc
>> 
>> 
>> 
>> -- 
>> Aaron Zeckoski - Software Architect - http://tinyurl.com/azprofile
>> _______________________________________________
>> sakai2-tcc mailing list
>> sakai2-tcc at collab.sakaiproject.org
>> http://collab.sakaiproject.org/mailman/listinfo/sakai2-tcc
> 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://collab.sakaiproject.org/pipermail/sakai2-tcc/attachments/20130213/112bedbe/attachment.html 


More information about the sakai2-tcc mailing list