#28588: User.has_perm() with superusers hides nonexistent permissions
-------------------------------------+-------------------------------------
     Reporter:  Paul Hallett         |                    Owner:  moshe
         Type:                       |  nahmias
  Cleanup/optimization               |                   Status:  assigned
    Component:  contrib.auth         |                  Version:  1.11
     Severity:  Normal               |               Resolution:
     Keywords:                       |             Triage Stage:  Accepted
    Has patch:  0                    |      Needs documentation:  0
  Needs tests:  0                    |  Patch needs improvement:  0
Easy pickings:  0                    |                    UI/UX:  0
-------------------------------------+-------------------------------------
Changes (by Tim Graham):

 * type:  Uncategorized => Cleanup/optimization
 * easy:  1 => 0
 * stage:  Unreviewed => Accepted


Comment:

 From the mailing list:

 Florian: "I do not think it would be feasible to check existing
 permissions. For one, not every backend uses the Permission class Django
 supplies and get_all_permissions can cause performance issues so it should
 be used sparingly."

 Me: "I suppose we can tentatively accept the ticket, but I looked at the
 code briefly and agree with Florian's assessment. If someone proposes a
 patch, we can evaluate it, however, I don't see a simple way forward that
 wouldn't have a security risk or an adverse effect on performance. Given
 the philosophy, "complexity is the enemy of security," I'd lean toward
 keeping the permissions checking code simple instead of adding some other
 logic based on DEBUG."

 If a code solution can't be found, the documentation could note this
 caveat.

-- 
Ticket URL: <https://code.djangoproject.com/ticket/28588#comment:3>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/django-updates/063.448873a5d311419c707cf5280103d63a%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to