See https://hackerone.com/reports/1573143. The pathway for disabling global builtin queries is missing a policy check. Add it.
Details
Details
- Accessed the "/search/delete/id/.../" URI for a global builtin query as a non-administrator.
- Before patch: could improperly disable queries. -After patch: proper policy exception.
Diff Detail
Diff Detail
- Repository
- rP Phabricator
- Lint
Lint Not Applicable - Unit
Tests Not Applicable