Department Portal doesn't actually check if you are in a department
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 48/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- python
- Domain
- authorization, backend
Research direction
Start at the department portal entry point and compare its access check with the explicit check on the position management page. Reproduce the Peewee error as a student and verify access for both students and staff with valid and invalid department selections. Done means unauthorized users cannot view the portal and students receive a handled access response instead of a crash.
Written by the indexing model from the issue text.
Description
The department portal doesn't check whether you are supposed to be able to view the pages you are supposed to be able to see.
This was originally circumvented by checking which departments are viewable from the drop-down to select a department.
However, there is no check to ensure that a user is actually in the department they have selected.
What does this mean?
This means that by selecting an ORG and an ACCOUNT in the URL, the user gains access to the department portal. Take, for instance, a student!The other pages on the department portal seem to have solutions to this issue. Specifically, the position management page has an explicit check for this. The challenge for the department portal is that there needs to be a valid list of departments, but a student has no departments they are a part of. This causes a peewee error because you would need to check the department ID to ensure it matches a student (which the student doesn't have).
In short, students don't have a department. Department portal checks for this to see if the user has access to the department, and it then crashes the page. Find a way to check that the user (both staff or student) has access to the department without crashing the page.
- Dominant language
- Python
- Stars
- 1
- Forks
- 1
- Avg merge
- 2h 57m
- Merged PRs (30d)
- 1
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- No pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from BCStudentSoftwareDevTeam/lsf
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
BCStudentSoftwareDevTeam/lsf#659 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
BCStudentSoftwareDevTeam/lsf#572 ·
-
Difficulty 3/5 1-2 days Newbie friendliness 58/100
BCStudentSoftwareDevTeam/lsf#677 ·
-
draft on hold
Difficulty 3/5 1-2 days Newbie friendliness 55/100
BCStudentSoftwareDevTeam/lsf#674 ·
-
Position Description should be reviewed by LaborPossibly taken @nahom70 claimed this 20 days ago. Open
Difficulty 4/5 3-5 days Newbie friendliness 50/100
BCStudentSoftwareDevTeam/lsf#673 · 1 assignee ·
All issues in BCStudentSoftwareDevTeam/lsf
Similar issues
-
feature:LinkChecker
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
digitalfabrik/integreat-cms#4594 ·
Maintainers usually reply within 5 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
EleutherAI/lm-evaluation-harness#4319 ·
Maintainers usually reply within 1 day
-
needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day
-
json_params_matcher fails on falsy top-level JSON primitives (0, False, "")Possibly taken @mayureshsonawane17 claimed this today. OpenWaiting for: Product Owner
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 5 days