Skip to content
  • Fokkema's avatar
    Fixed bug; Security bug and broke external viewer. · a21c7d2c
    Fokkema authored
    - aColsToSkip was now trusted to be set in SESSION, but we did not check if it actually was set in SESSION. The recent removal of code that enforced the removal of certain columns for lower level users, allowed these users to forge an AJAX request that would show the links anyway. Reinstated this code.
    - aColsToSkip was needed for the external viewer. Not being able to set it anymore, resulted in lots of additional columns for the country node views.
    a21c7d2c