Closed (won't fix)
Project:
Usercontent
Version:
5.x-1.x-dev
Component:
Code
Priority:
Critical
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
26 Feb 2008 at 19:21 UTC
Updated:
3 Feb 2013 at 18:00 UTC
Private content is also shown. How does it exclude?
Comments
Comment #1
ultraBoy commentedWhat is private content?
Comment #2
introfini commentedMaybe is talking about some node types that should be excluded. It would be a nice feature to allow choosing the node types that are exposed.
introfini
Comment #3
pfaocleNo - your query (at least in the version I'm playing around with) is not passed through db_rewrite_sql, meaning that any content that is protected by Drupal's node access using a module like TAC, TAC_LITE, Content/Forum Access etc will still be listed on user profiles. When a visitor who does not have access to view these nodes clicks on an item in the User Content listing, he/she will be presented with an Access Denied page.
I'd say this was a critical bug, as enabling this module on a site with content protected by ANY node access control module will expose listings of private content to anonymous and other non-privileged users.
Comment #4
pomliane commentedThis version of Usercontent is not supported anymore. The issue is closed for this reason.
Please upgrade to a supported version and feel free to reopen the issue on the new version if applicable.
This issue has been automagically closed by a script.