Wednesday, January 18, 2012

Hide diagnostics menu

In this menu it is very handy to do lot of things like look at hidden field values like invoice_id's etc, yet it possible to change values wich is not allowed by standard form behavior, so it makes you instance potentialy vulnerable when used by curious users.
By defaul it looks like this
 Then disable it by changing profile
An finally diagnostics menu disabled