From 7ef20cc169e7e32cf66d01fc64ee83baba2ff9b5 Mon Sep 17 00:00:00 2001 From: Jean-Philippe Lang Date: Sat, 30 Jan 2010 11:23:17 +0000 Subject: [PATCH] Fixed: potential security leak on my page calendar (#4691). git-svn-id: svn+ssh://rubyforge.org/var/svn/redmine/trunk@3351 e93f8b46-1217-0410-a6f0-8f06a7374b81 --- app/views/my/blocks/_calendar.rhtml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/views/my/blocks/_calendar.rhtml b/app/views/my/blocks/_calendar.rhtml index bad729363..9c6b793bf 100644 --- a/app/views/my/blocks/_calendar.rhtml +++ b/app/views/my/blocks/_calendar.rhtml @@ -1,7 +1,7 @@

<%= l(:label_calendar) %>

<% calendar = Redmine::Helpers::Calendar.new(Date.today, current_language, :week) - calendar.events = Issue.find :all, + calendar.events = Issue.visible.find :all, :conditions => ["#{Issue.table_name}.project_id in (#{@user.projects.collect{|m| m.id}.join(',')}) AND ((start_date>=? and start_date<=?) or (due_date>=? and due_date<=?))", calendar.startdt, calendar.enddt, calendar.startdt, calendar.enddt], :include => [:project, :tracker, :priority, :assigned_to] unless @user.projects.empty? %> -- 2.39.5