mirror of
https://we.phorge.it/source/phorge.git
synced 2025-02-04 10:58:25 +01:00
15cc475cbd
Summary: Ref PHI1173. Currently, you can edit an MFA'd comment without redoing MFA. This is inconsistent with the intent of the MFA badge, since it means an un-MFA'd comment may have an "MFA" badge on it. Instead, implement these rules: - If a comment was signed with MFA, you MUST MFA to edit it. - When removing a comment, add an extra MFA prompt if the user has MFA. This one isn't strictly required, this action is just very hard to undo and seems reasonable to MFA. Test Plan: - Made normal comments and MFA comments. - Edited normal comments and MFA comments (got prompted). - Removed normal comments and MFA comments (prompted in both cases). - Tried to edit an MFA comment without MFA on my account, got a hard "MFA absolutely required" failure. Reviewers: amckinley Reviewed By: amckinley Differential Revision: https://secure.phabricator.com/D20340 |
||
---|---|---|
.. | ||
PhabricatorApplicationTransactionCommentEditController.php | ||
PhabricatorApplicationTransactionCommentHistoryController.php | ||
PhabricatorApplicationTransactionCommentQuoteController.php | ||
PhabricatorApplicationTransactionCommentRawController.php | ||
PhabricatorApplicationTransactionCommentRemoveController.php | ||
PhabricatorApplicationTransactionController.php | ||
PhabricatorApplicationTransactionDetailController.php | ||
PhabricatorApplicationTransactionRemarkupPreviewController.php | ||
PhabricatorApplicationTransactionShowOlderController.php | ||
PhabricatorApplicationTransactionValueController.php | ||
PhabricatorEditEngineConfigurationDefaultCreateController.php | ||
PhabricatorEditEngineConfigurationDefaultsController.php | ||
PhabricatorEditEngineConfigurationDisableController.php | ||
PhabricatorEditEngineConfigurationEditController.php | ||
PhabricatorEditEngineConfigurationIsEditController.php | ||
PhabricatorEditEngineConfigurationListController.php | ||
PhabricatorEditEngineConfigurationLockController.php | ||
PhabricatorEditEngineConfigurationReorderController.php | ||
PhabricatorEditEngineConfigurationSaveController.php | ||
PhabricatorEditEngineConfigurationSortController.php | ||
PhabricatorEditEngineConfigurationSubtypeController.php | ||
PhabricatorEditEngineConfigurationViewController.php | ||
PhabricatorEditEngineController.php | ||
PhabricatorEditEngineListController.php |