Private method in handler is accessible from public ( direct link )

Description

None

Activity

Show:
Dominic Watson
June 11, 2019, 10:49 AM

Further investigation shows that it seems to stem from the change in /coldbox/system/web/Controller.cfc$invoker(). From 3.8 to 4, it went from conditional logic:

To just script based and ignoring private/public distinction:

Luis Majano
June 11, 2019, 8:51 PM

Good observation, I am escalating this to fix

Johnson Cheng
June 12, 2019, 2:35 AM
Edited

Assignee

Luis Majano

Reporter

Johnson Cheng

Labels

None

Components

Fix versions

Priority

Critical
Configure