koha-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Koha-devel] Koha 2.0.0RC1 is dead. Long live to koha 2.0.0RC2!!!


From: Owen Leonard
Subject: Re: [Koha-devel] Koha 2.0.0RC1 is dead. Long live to koha 2.0.0RC2!!!
Date: Wed Jan 21 11:51:01 2004

> This one is not yet completely fixed:
> > * 662 : poor SQL calls, that could be used for 
> > SQL injection (security problem)

By the way, thanks to MJR for putting in a lot of time on this bug.  It's never 
as fun to this kind of important polishing as it is to add new stuff.
 
> > Are these three the only blockers?
>
> I see the following as blockers/critical in bugzilla:
>   196 cri P1 user input not checked for HTML tags
>   436 cri P2 circulation.pl only partially templated
>   662 cri P2 Probable insecure use of prepare()
>   293 cri P2 Error Issuing Book - 1

436 is a pernicious one, but enough progress has been made that I wouldn't 
consider it a blocker, even though it still irritates me :)  293 is definitely 
a problem for circ staff.  I don't know about the proper use of 
blocker/critical/major etc., but I'll toss in these bugs that make day-to-day 
life hard for our staff:

612 maj P2 Renewal failure gives no feedback
670 maj P2 "Waiting" status often inaccurate
605 maj P2 circulation.pl only shows one waiting item
613 maj P2 Deleting one of a patron's multiple reserves on a single item 
deletes all
661 maj P2 circulation.pl no longer shows flags
617 maj P2 OPAC renew function available even if item is on reserve
668 maj P2 Cancelling reserve upon check-out does not work

  -- Owen

----
Nelsonville Public Library
http://www.athenscounty.lib.oh.us



reply via email to

[Prev in Thread] Current Thread [Next in Thread]