diff options
| author | Carlton Gibson <carlton.gibson@noumenal.es> | 2019-11-14 15:03:26 +0100 |
|---|---|---|
| committer | Carlton Gibson <carlton.gibson@noumenal.es> | 2019-12-02 08:56:08 +0100 |
| commit | 11c5e0609bcc0db93809de2a08e0dc3d70b393e4 (patch) | |
| tree | 67fc3a79fd87f541c3dd6092a263de9a84e96e36 /tests/admin_views/admin.py | |
| parent | 39e39d0ac1b720e7460ec8ccf45926c78edb2047 (diff) | |
Fixed CVE-2019-19118 -- Required edit permissions on parent model for editable inlines in admin.
Thank you to Shen Ying for reporting this issue.
Diffstat (limited to 'tests/admin_views/admin.py')
| -rw-r--r-- | tests/admin_views/admin.py | 9 |
1 files changed, 0 insertions, 9 deletions
diff --git a/tests/admin_views/admin.py b/tests/admin_views/admin.py index bf10151356..beec6f80f4 100644 --- a/tests/admin_views/admin.py +++ b/tests/admin_views/admin.py @@ -1178,12 +1178,3 @@ class ArticleAdmin9(admin.ModelAdmin): site9 = admin.AdminSite(name='admin9') site9.register(Article, ArticleAdmin9) - - -class ArticleAdmin10(admin.ModelAdmin): - def has_change_permission(self, request, obj=None): - return False - - -site10 = admin.AdminSite(name='admin10') -site10.register(Article, ArticleAdmin10) |
