bgodette wrote:Because it was a different backend.jhfrontz wrote:Then why was it possible to circumvent that in cartouche_old?
And whether the code which is doing different permissions checking now is part of something in the webserver or within the database, we don't know and it doesn't really matter. Permissions are taken care of server side and there's little we could do from the browser side except make things more restrictive. Which, ultimately, could be easily circumvented with userscripts.

