Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Department Portal doesn't actually check if you are in a department

Open
#675 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
48/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
python

Research direction

Start at the department portal entry point and compare its access check with the explicit check on the position management page. Reproduce the Peewee error as a student and verify access for both students and staff with valid and invalid department selections. Done means unauthorized users cannot view the portal and students receive a handled access response instead of a crash.

Written by the indexing model from the issue text.

Description

The department portal doesn't check whether you are supposed to be able to view the pages you are supposed to be able to see.
This was originally circumvented by checking which departments are viewable from the drop-down to select a department.
However, there is no check to ensure that a user is actually in the department they have selected.

What does this mean?
This means that by selecting an ORG and an ACCOUNT in the URL, the user gains access to the department portal. Take, for instance, a student! Image

The other pages on the department portal seem to have solutions to this issue. Specifically, the position management page has an explicit check for this. The challenge for the department portal is that there needs to be a valid list of departments, but a student has no departments they are a part of. This causes a peewee error because you would need to check the department ID to ensure it matches a student (which the student doesn't have).

In short, students don't have a department. Department portal checks for this to see if the user has access to the department, and it then crashes the page. Find a way to check that the user (both staff or student) has access to the department without crashing the page.

Dominant language
Python
Stars
1
Forks
1
Avg merge
2h 57m
Merged PRs (30d)
1

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

  • No Dockerfile or Docker Compose file
  • No pull request template
  • No contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from BCStudentSoftwareDevTeam/lsf

All issues in BCStudentSoftwareDevTeam/lsf

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.