Gargaj / wuhu

Lightweight Party Management System

Home Page:http://wuhu.function.hu/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Timetable plugin does not appear to check logged in / authorized state

falken42 opened this issue · comments

The Timetable plugin does not appear to properly check the logged in state of a user before displaying the timetable, even when the menu type for the Timetable plugin is set to "Logged in only".

While the top menu does not show a URL link to the Timetable page, anyone with access to the Timetable page URL will be able to view the timetable without logging in. Other pages (such as Voting) properly show an expected UNAUTHORIZED REQUEST! error.

Screen Shot 2021-11-14 at 14 41 11
Screen Shot 2021-11-14 at 14 41 35