Print Topic - Archive

E-Blah Community  /  E-Blah Bugs  /  Find latest posts by this member
Posted by: kslager, July 25, 2006, 9:00pm
This isnt a bug, but possibly more of a security issue.  

Lets say you have a board on your forum that is set to allow only certain members to view threads in that board.


If a regular user (one who is not allowed to view threads in this protected board) goes to the member center of a user that has posted in that protected board and click the "Find latest posts by this member" you will be able to read their thread in the protected board.

Kind of defeating the purpose of having certain board permissions.

If that didn't make sense, I will attempt to clarify.

Posted by: Justin, July 26, 2006, 7:03am; Reply: 1
No, search is secure.  You can go in as a regular user and see that it doesn't show you the results (even if an Administrator goes and finds their posts and a regular user goes and looks at the history, it won't work).  If it does work, make sure you're using P9.71B. If it still works, upgrade, because I remember adding this ... lol.
Posted by: Adite, August 25, 2006, 9:41am; Reply: 2
Core Version: Platinum 9.71B
Internal Version: 16
Supported Themes: Platinum 9

I have the same bug. Someone pointed it out to today, and Ive checked it by creating a new account. You can see them.  :-/

Is this issue dealt with in the new version?
Posted by: Justin, August 25, 2006, 3:53pm; Reply: 3
I had to make sure, and here's my results ...

Oh ... the first shows 11 pages, but that same search ID used by a guest showed only 9 pages.  Hence about 2 pages were removed.
Posted by: kslager, August 25, 2006, 4:34pm; Reply: 4
i eventually just removed the "Find latest posts by this member" line from MemberPanel.lng

quick fix  :X
Posted by: Justin, August 25, 2006, 7:28pm; Reply: 5
Quoted from kslager
i eventually just removed the "Find latest posts by this member" line from MemberPanel.lng

quick fix  :X


Not sure why you did this, lol, but ok.

I was simply proving a point: it checks to see if the user is allowed access to that message.
Print page generated: March 12, 2010, 3:29pm