Closed (duplicate)
Project:
Private
Version:
6.x-1.x-dev
Component:
Miscellaneous
Priority:
Critical
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
21 Dec 2008 at 11:35 UTC
Updated:
21 Dec 2008 at 23:03 UTC
This occurs irrespective of any permissions settings, which seem to be completely ignored.
I have tested this systematically using a few authenticated users,
all can read all other private nodes, including those from admin !
Anonymous is correctly blocked.
BTW I have no other access modules installed.
Please if this is not a bug explain how to change this behavior,
or point to documentation that explains that it should behave thus,
otherwise it is a clear security flaw.
Glad for advice.
Comments
Comment #1
webel commentedAccidental double-submission of #349735: All authenticated users can view all private content from all other authenticated users, including the admin's private pages, may be deleted.