Project

General

Profile

« Previous | Next » 

Revision 14795

Fixed that time logging form may disclose subjects of issues that are not visible (#21150).

Patch by Holger Just.

View differences:

trunk/app/views/timelog/_form.html.erb
13 13
  <% end %>
14 14
  <p>
15 15
    <%= f.text_field :issue_id, :size => 6 %>
16
    <span id="time_entry_issue"><%= "#{@time_entry.issue.tracker.name} ##{@time_entry.issue.id}: #{@time_entry.issue.subject}" if @time_entry.issue %></span>
16
    <span id="time_entry_issue"><%= "#{@time_entry.issue.tracker.name} ##{@time_entry.issue.id}: #{@time_entry.issue.subject}" if @time_entry.issue.try(:visible?) %></span>
17 17
  </p>
18 18
  <p><%= f.text_field :spent_on, :size => 10, :required => true %><%= calendar_for('time_entry_spent_on') %></p>
19 19
  <p><%= f.text_field :hours, :size => 6, :required => true %></p>

Also available in: Unified diff