By Paul on Friday, 09 May 2014
Posted in General Issues
Replies 5
Likes 0
Views 0.9K
Votes 0
Testing out ES 1.2.10. I'm noticing that privacy/privileges are not being respected in the stream. For example: scenario 1: you have activity for Kunena forums and you have multiple forums including a forum that has restricted access. Member A has access permissions to Restricted Forum category. Member B, does not have access to Restricted Forum category. Member A makes a post in Restricted Forum. Member B goes to Member A's profile page. On the profile page go to the profile activity for Member A. Not only does Member B see the activity that Member A posted in Restricted Forum, but he also sees the title of the post and at least partial content of that post. If member B clicks through on "View Thread" Member B will get a "You do not have permissions" message however Member B has already accessed content from Restricted Forum that he would otherwise not been able to access. This is a nightmare scenario in the making for example if the Restricted Forum is for moderation discussion of problem users or another nightmarish scenario could be where there is adult content in that Restricted Forum and a child accesses it through this workaround.
Hi Paul,

This issue has fixed internally. The fix will be added into next release of EasySocial. For the quick fix, download the attached kunena.php and copy the file to 'JOOMLA/media/com_easysocial/apps/user/kunena/' and overwrite the existing file. Remember to backup your original first 1st before you apply the fix

Let me know if the fix work for you or not

Hope this help and have a nice day
Sam
·
Friday, 09 May 2014 13:59
·
0 Likes
·
0 Votes
·
0 Comments
·
Thank you. I will test out at next opportunity.
·
Friday, 09 May 2014 14:07
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Paul,

Sure, do let us know how it goes
Have a nice day and a wonderful weekend
Sam
·
Friday, 09 May 2014 16:32
·
0 Likes
·
0 Votes
·
0 Comments
·
I installed.. It took care of the problem. Thanks!
·
Monday, 26 May 2014 05:17
·
0 Likes
·
0 Votes
·
0 Comments
·
Thanks for updating Glad that your issues are resolved now.
·
Monday, 26 May 2014 10:59
·
0 Likes
·
0 Votes
·
0 Comments
·
View Full Post