https://bugzilla.wikimedia.org/show_bug.cgi?id=17116





--- Comment #5 from Andrew Garrett <and...@epstone.net>  2009-01-22 03:58:32 
UTC ---
I don't agree that "There is no way for the extension author to declare that it
has no problem with the user having read access, but to also allow the other
security code to run".

If no extension sets $result, then this is what happens.

If one or more extensions sets $result to true, then they have declared that
they want the user to be able to read, no matter what.

If one or more extensions set $result to false, then they have declined access,
regardless of the other code.


-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.
You are on the CC list for the bug.

_______________________________________________
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to