Closed (fixed)
Project:
Node Access Keys
Version:
7.x-1.1
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Reporter:
Created:
1 Jul 2014 at 08:44 UTC
Updated:
8 Jul 2014 at 13:29 UTC
Jump to comment: Most recent
When i enable the mobule all my unpublished nodes can be accessed by anonymous users.
Until someone figures out how this module work (i didn't) all of his unpublished nodes are accessed by anonymous users. I think this is a little bit dangerous and have to be documented and mentioned.
Comments
Comment #2
daniel korteThanks for bringing this to my attention. I'm working with the Security Team on getting a fix for this out soon.
After enabling the module you'll need to visit the module settings page (/admin/config/people/nodeaccesskeys/settings) and set a default content type.
Also, you can check out the documentation here on how to create an access key.
Comment #3
daniel kortechrbak, could you possibly retest and comment here if you found this issue to be fixed. Thank you!
Comment #4
chrbak commentedHello Daniel, I have retested the module with the committed patch and I can confirm that the issue is fixed. Additionally now I can use the module as you describe here.
I am posting here because the link you sent me to comment redirects me to security.drupal.org/ propably because I am not a member..
Comment #5
daniel korteThanks for your help on this chrbak, the fix has committed to the current version of the module, 7.x-1.2.
Comment #6
David_Rothstein commentedYes, thank you for helping with this. But if you discover any potential security issues in the future, please follow the procedure at https://www.drupal.org/security-team/report-issue to report it privately to the security team (rather than reporting it in the public issue queue)... thanks!