Re: Proposal: hide DjangoCMS version in toolbar for non-admin users

2016-11-14 Thread Angelo Dini
+ 1 -- Message URL: https://groups.google.com/d/msg/django-cms-developers/topic-id/message-id Unsubscribe: send a message to django-cms-developers+unsubscr...@googlegroups.com --- You received this message because you are subscribed to the Google Groups "django CMS developers" group. To unsub

Re: Proposal: hide DjangoCMS version in toolbar for non-admin users

2016-11-12 Thread czpython
Thanks for following up :) +1 On Saturday, November 12, 2016 at 5:42:40 AM UTC-5, Sylvain Fankhauser wrote: > > Hello, > > The current behaviour of the toolbar is to show the DjangoCMS version on > hover, which means you can go to most DjangoCMS websites, add a "?edit" > querystring, and see i

Re: Proposal: hide DjangoCMS version in toolbar for non-admin users

2016-11-12 Thread Iacopo Spalletti
On 12/11/2016 11:42, Sylvain Fankhauser wrote: > Hello, > > The current behaviour of the toolbar is to show the DjangoCMS version on > hover, which means you can go to most DjangoCMS websites, add a "?edit" > querystring, and see if they're using an outdated DjangoCMS version. I > think that secur

Proposal: hide DjangoCMS version in toolbar for non-admin users

2016-11-12 Thread Sylvain Fankhauser
Hello, The current behaviour of the toolbar is to show the DjangoCMS version on hover, which means you can go to most DjangoCMS websites, add a "?edit" querystring, and see if they're using an outdated DjangoCMS version. I think that security-wise it would be better to only show the version whe