Monday, 2 July 2007

Security: Disable browsing public accounts from demonstration accounts

Added code to disallow browsing of publicly-visible account by users logged into read-only demonstration accounts. This restricts access to public accounts to those users who have gone to the trouble of creating an account of their own. This is enforced not only by removing the ``Browse public user accounts'' item from the Utilities menu for read-only accounts, but also aborting transactions ginned up from a read-only login with the transaction codes for public account access.

No comments: