Skip to:
Content

bbPress.org

Opened 12 years ago

Closed 12 years ago

#1678 closed defect (bug) (fixed)

guests can edit a topic if guest posting is allowed

Reported by: anointed's profile anointed Owned by:
Milestone: 2.0.1 Priority: high
Severity: normal Version: 2.0
Component: General - UI/UX Keywords:
Cc:

Description

Totally virgin setup bbpress 2x wp 3.3beta2

I noticed that if I allow guest posting, that a guest can edit any topic, even those created by an admin by simply appending /edit/ to the end of the topic.

screenshot:
http://awesomescreenshot.com/026nol645

notice, I am logged out, yet I can see the edit fields, and sure enough if I click submit, it submits my edits.

Change History (5)

#1 @anointed
12 years ago

you will also notice the userfields doubled up. I mentioned this in a prior ticket

#2 @johnjamesjacoby
12 years ago

(In [3600]) Prevent guest users from editing topics and replies if anonymous posting is active. See #1678. (2.1)

#3 @johnjamesjacoby
12 years ago

(In [3601]) Revert part of r3600 and change logic. See #1678. (2.1)

#4 @johnjamesjacoby
12 years ago

(In [3602]) Prevent guest users from editing topics and replies if anonymous posting is active. See #1678. (2.0)

#5 @johnjamesjacoby
12 years ago

  • Milestone changed from Awaiting Review to 2.0.1
  • Resolution set to fixed
  • Status changed from new to closed
Note: See TracTickets for help on using tickets.