From be4cc2f99e34316be4b8beb2e9040c5ea967a736 Mon Sep 17 00:00:00 2001 From: Jean-Philippe Lang Date: Thu, 10 Jul 2008 12:31:49 +0000 Subject: Fixed: search engine may reveal private projects (#1613). git-svn-id: http://redmine.rubyforge.org/svn/trunk@1649 e93f8b46-1217-0410-a6f0-8f06a7374b81 --- app/models/journal.rb | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to 'app/models/journal.rb') diff --git a/app/models/journal.rb b/app/models/journal.rb index 67a3eee3b..8583f63de 100644 --- a/app/models/journal.rb +++ b/app/models/journal.rb @@ -28,7 +28,8 @@ class Journal < ActiveRecord::Base acts_as_searchable :columns => 'notes', :include => {:issue => :project}, :project_key => "#{Issue.table_name}.project_id", - :date_column => "#{Issue.table_name}.created_on" + :date_column => "#{Issue.table_name}.created_on", + :permission => :view_issues acts_as_event :title => Proc.new {|o| status = ((s = o.new_status) ? " (#{s})" : nil); "#{o.issue.tracker} ##{o.issue.id}#{status}: #{o.issue.subject}" }, :description => :notes, -- cgit v1.2.3