forked from redmineup/redmine_access_filters
-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Description
After 5d91919 we have
unlimited 302 when downloading a document via CSV within the browser
s-echo-1 | I, [2024-10-29T13:07:00.012608 #1] INFO -- : Started GET "/issues.csv?utf8=%E2%9C%93&set_filter=1&f%5B%5D=status_id&op%5Bstatus_id%5D=o&v%5Bstatus_id%5D%5B%5D=&c%5B%5D=id&c%5B%5D=project&c%5B%5D=tracker&c%5B%5D=status&c%5B%5D=cf_2&c%5B%5D=priority&c%5B%5D=subject&c%5B%5D=assigned_to&c%5B%5D=updated_on&sort=id%3Adesc&query_name=_&c%5B%5D=&encoding=ISO-8859-1&field_separator=%3B" for 80.108.2.151 at 2024-10-29 13:07:00 +0000
mis-echo-1 | I, [2024-10-29T13:07:00.014008 #1] INFO -- : Processing by IssuesController#index as CSV
mis-echo-1 | I, [2024-10-29T13:07:00.014068 #1] INFO -- : Parameters: {"utf8"=>"✓", "set_filter"=>"1", "f"=>["status_id"], "op"=>{"status_id"=>"o"}, "v"=>{"status_id"=>[""]}, "c"=>["id", "project", "tracker", "status", "cf_2", "priority", "subject", "assigned_to", "updated_on", ""], "sort"=>"id:desc", "query_name"=>"_", "encoding"=>"ISO-8859-1", "field_separator"=>";"}
mis-echo-1 | D, [2024-10-29T13:07:00.046601 #1] DEBUG -- : (0.8ms) SELECT MAX("settings"."updated_on") FROM "settings"
mis-echo-1 | D, [2024-10-29T13:07:00.051053 #1] DEBUG -- : Setting Load (0.6ms) SELECT "settings".* FROM "settings" WHERE "settings"."name" = $1 ORDER BY "settings"."id" DESC LIMIT $2 [["name", "rest_api_enabled"], ["LIMIT", 1]]
mis-echo-1 | D, [2024-10-29T13:07:00.062554 #1] DEBUG -- : AnonymousUser Load (1.3ms) SELECT "users".* FROM "users" WHERE "users"."type" = $1 AND "users"."lastname" = $2 LIMIT $3 [["type", "AnonymousUser"], ["lastname", "Anonymous"], ["LIMIT", 1]]
mis-echo-1 | I, [2024-10-29T13:07:00.092067 #1] INFO -- : Current user: anonymous
mis-echo-1 | D, [2024-10-29T13:07:00.093235 #1] DEBUG -- : Setting Load (0.4ms) SELECT "settings".* FROM "settings" WHERE "settings"."name" = $1 ORDER BY "settings"."id" DESC LIMIT $2 [["name", "login_required"], ["LIMIT", 1]]
mis-echo-1 | I, [2024-10-29T13:07:00.094285 #1] INFO -- : Redirected to https://mis-echo.medelexis.ch/login?back_url=https%3A%2F%2Fmis-echo.medelexis.ch%2Fissues.csv%3Futf8%3D%25E2%259C%2593%26set_filter%3D1%26f%255B%255D%3Dstatus_id%26op%255Bstatus_id%255D%3Do%26v%255Bstatus_id%255D%255B%255D%3D%26c%255B%255D%3Did%26c%255B%255D%3Dproject%26c%255B%255D%3Dtracker%26c%255B%255D%3Dstatus%26c%255B%255D%3Dcf_2%26c%255B%255D%3Dpriority%26c%255B%255D%3Dsubject%26c%255B%255D%3Dassigned_to%26c%255B%255D%3Dupdated_on%26sort%3Did%253Adesc%26query_name%3D_%26c%255B%255D%3D%26encoding%3DISO-8859-1%26field_separator%3D%253B
mis-echo-1 | I, [2024-10-29T13:07:00.094362 #1] INFO -- : Filter chain halted as :check_if_login_required rendered or redirected
mis-echo-1 | I, [2024-10-29T13:07:00.094662 #1] INFO -- : Completed 302 Found in 81ms (ActiveRecord: 24.5ms | Allocations: 38794)
mis-echo-1 | I, [2024-10-29T13:07:00.134769 #1] INFO -- : Started GET "/login?back_url=https%3A%2F%2Fmis-echo.medelexis.ch%2Fissues.csv%3Futf8%3D%25E2%259C%2593%26set_filter%3D1%26f%255B%255D%3Dstatus_id%26op%255Bstatus_id%255D%3Do%26v%255Bstatus_id%255D%255B%255D%3D%26c%255B%255D%3Did%26c%255B%255D%3Dproject%26c%255B%255D%3Dtracker%26c%255B%255D%3Dstatus%26c%255B%255D%3Dcf_2%26c%255B%255D%3Dpriority%26c%255B%255D%3Dsubject%26c%255B%255D%3Dassigned_to%26c%255B%255D%3Dupdated_on%26sort%3Did%253Adesc%26query_name%3D_%26c%255B%255D%3D%26encoding%3DISO-8859-1%26field_separator%3D%253B" for 80.108.2.151 at 2024-10-29 13:07:00 +0000
mis-echo-1 | I, [2024-10-29T13:07:00.135664 #1] INFO -- : Processing by AccountController#login as HTML
mis-echo-1 | I, [2024-10-29T13:07:00.135699 #1] INFO -- : Parameters: {"back_url"=>"https://mis-echo.medelexis.ch/issues.csv?utf8=%E2%9C%93&set_filter=1&f%5B%5D=status_id&op%5Bstatus_id%5D=o&v%5Bstatus_id%5D%5B%5D=&c%5B%5D=id&c%5B%5D=project&c%5B%5D=tracker&c%5B%5D=status&c%5B%5D=cf_2&c%5B%5D=priority&c%5B%5D=subject&c%5B%5D=assigned_to&c%5B%5D=updated_on&sort=id%3Adesc&query_name=_&c%5B%5D=&encoding=ISO-8859-1&field_separator=%3B"}
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels