summaryrefslogtreecommitdiff
path: root/tests/admin_views/admin.py
diff options
context:
space:
mode:
authorCarlton Gibson <carlton.gibson@noumenal.es>2019-11-25 12:01:49 +0100
committerCarlton Gibson <carlton.gibson@noumenal.es>2019-12-02 08:58:14 +0100
commit36f580a17f0b3cb087deadf3b65eea024f479c21 (patch)
treecda21439c213c5246b5ac2736399cf5d2894c0cf /tests/admin_views/admin.py
parent70311e1d00ef5b6bbbc8961eac81b5c814396a43 (diff)
Fixed CVE-2019-19118 -- Required edit permissions on parent model for editable inlines in admin.
Thank you to Shen Ying for reporting this issue.
Diffstat (limited to 'tests/admin_views/admin.py')
-rw-r--r--tests/admin_views/admin.py9
1 files changed, 0 insertions, 9 deletions
diff --git a/tests/admin_views/admin.py b/tests/admin_views/admin.py
index 0b0ad41e2e..a18fb363aa 100644
--- a/tests/admin_views/admin.py
+++ b/tests/admin_views/admin.py
@@ -1149,12 +1149,3 @@ class ArticleAdmin9(admin.ModelAdmin):
site9 = admin.AdminSite(name='admin9')
site9.register(Article, ArticleAdmin9)
-
-
-class ArticleAdmin10(admin.ModelAdmin):
- def has_change_permission(self, request, obj=None):
- return False
-
-
-site10 = admin.AdminSite(name='admin10')
-site10.register(Article, ArticleAdmin10)