Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 2 additions & 11 deletions Bugzilla/Attachment.pm
100755 → 100644
Original file line number Diff line number Diff line change
Expand Up @@ -612,22 +612,13 @@ sub get_attachments_by_bug {
my $dbh = Bugzilla->dbh;

# By default, private attachments are not accessible, unless the user
# is in the insider group, submitted the attachment, or it's a bounty
# attachment and they reported the bug.
# is in the insider group or submitted the attachment.
my $and_restriction = '';
my @values = ($bug->id);

unless ($user->is_insider) {
$and_restriction = 'AND (isprivate = 0 OR submitter_id = ?';
$and_restriction = 'AND (isprivate = 0 OR submitter_id = ?)';
push(@values, $user->id);
if ($user->id == $bug->reporter->id) {

# Keep these conditions in sync with _attachment_is_bounty_attachment
# in extensions/BMO/Extension.pm
$and_restriction
.= " OR (filename = 'bugbounty.data' AND mimetype = 'text/plain')";
}
$and_restriction .= ')';
}

# BMO - allow loading of just non-obsolete attachments
Expand Down
1 change: 0 additions & 1 deletion extensions/BMO/Extension.pm
100755 → 100644
Original file line number Diff line number Diff line change
Expand Up @@ -330,7 +330,6 @@ sub bounty_attachment {
}

sub _attachment_is_bounty_attachment {
# Keep this in sync with Bugzilla/Attachment.pm
my ($attachment) = @_;

return 0 unless $attachment->filename eq 'bugbounty.data';
Expand Down
2 changes: 0 additions & 2 deletions extensions/BMO/template/en/default/hook/bug_modal/attachments-row.html.tmpl
100755 → 100644
Original file line number Diff line number Diff line change
Expand Up @@ -24,10 +24,8 @@
[% END %]
</td>
<td class="attach-actions">
[% IF user.is_insider %]
<a href="[% basepath FILTER none %]page.cgi?id=attachment_bounty_form.html&bug_id=[% bug.id FILTER none %]">
Edit Bounty
</a>
[% END %]
</td>
</tr>
5 changes: 1 addition & 4 deletions extensions/BugModal/template/en/default/bug_modal/attachments.html.tmpl
100755 → 100644
Original file line number Diff line number Diff line change
Expand Up @@ -19,10 +19,7 @@
<table role="table" class="responsive" id="attachments">
[% FOREACH attachment IN bug.attachments %]
[%
NEXT IF attachment.isprivate
&& !(user.is_insider
|| attachment.attacher.id == user.id
|| (attachment.is_bounty_attachment && user.id == bug.reporter.id));
NEXT IF attachment.isprivate && !(user.is_insider || attachment.attacher.id == user.id);
attachment_rendered = 0;
Hook.process("row");
NEXT IF attachment_rendered;
Expand Down
2 changes: 1 addition & 1 deletion extensions/BugModal/template/en/default/bug_modal/edit.html.tmpl
100755 → 100644
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,7 @@
END;

FOREACH attachment IN bug.attachments;
NEXT IF attachment.isprivate && !(user.is_insider || attachment.attacher.id == user.id || (attachment.is_bounty_attachment && bug.reporter.id == user.id)) ;
NEXT IF attachment.isprivate && !(user.is_insider || attachment.attacher.id == user.id) ;
is_external = attachment_hide_types.${attachment.contenttype} ? 1 : 0;
IF is_external;
external_attachments_total = external_attachments_total + 1;
Expand Down
2 changes: 1 addition & 1 deletion template/en/default/attachment/list.html.tmpl
100755 → 100644
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,7 @@ function toggle_display(link) {

[% FOREACH attachment = attachments %]
[% count = count + 1 %]
[% IF !attachment.isprivate || user.is_insider || attachment.attacher.id == user.id || (attachment.is_bounty_attachment && user.id == bug.reporter.id) %]
[% IF !attachment.isprivate || user.is_insider || attachment.attacher.id == user.id %]
[% IF attachment.isobsolete %]
[% obsolete_attachments = obsolete_attachments + 1 %]
[% END %]
Expand Down
Loading