I like this project because it is really simple and nice!
I 've version 0.4.5 Beta, and i notice that user can not see the message tab in project management and i wan't the message system enable for authoriezd people.
so I edit top-project.tpl and it seems to be a feature only available for admins (if $adminstate > 0). I remove this condition, and it works (people can add/edit/del messages for a project they are assigned to)... so this is OK, but if it works it is a security bug because at the origine people doesn't seem to be authorised to access this feature.
Where is the mistake ?
- to block access to message for non admin users ?
- to not check users level in managemessage.php ?
I think i should be the first one