mirror of
https://github.com/silverstripe/silverstripe-framework
synced 2024-10-22 12:05:37 +00:00
732dfe5aaa
We decided during implementation not to check permissions explicitly on cascading objects due to performance concerns. For example, when publishing a page with embedded images, publish permissions on the image are implied - even if Image->canPublish() would return false for this author. See https://github.com/silverstripe-security/security-issues/issues/57