Skip to:
Content

bbPress.org

Opened 9 years ago

Closed 8 years ago

Last modified 8 years ago

#2173 closed defect (bug) (fixed)

Super sticky post of private forum is being listed in shortcode topic list

Reported by: tuomasparviainen.com Owned by: johnjamesjacoby
Milestone: 2.4 Priority: normal
Severity: normal Version: 2.2.3
Component: API - Shortcodes Keywords: needs-patch
Cc: jared@…

Description

Topic title is visible for not logged in user. The topic with replies is not available.

This is security problem, while topic titles may contain sensitive information and users assume private forums to be private to the end.

Change History (4)

#1 @tuomasparviainen.com
9 years ago

  • Component changed from Front-end to Shortcodes
  • Keywords needs-ui added
  • Priority changed from high to normal
  • Severity changed from major to normal
/**
	 * Filter the query for the topic index
	 *
	 * @since bbPress (r3637)
	 *
	 * @param array $args
	 * @return array
	 */
	public function display_topic_index_query( $args = array() ) {
		$args['author']        = 0;
		$args['show_stickies'] = true;
		$args['order']         = 'DESC';
		return $args;
	}

I found this from shortcodes.php. Argument show_stickies can be altered here, but when core is updated the selection is set to default.

This selection need to be in back-end options.

#2 @johnjamesjacoby
9 years ago

  • Keywords needs-patch added; needs-ui removed
  • Milestone changed from Awaiting Review to 2.4

This needs to be addressed in bbp_has_topics(). Moving to 2.4 to address then.

#3 @jaredatch
9 years ago

  • Cc jared@… added

#4 @johnjamesjacoby
8 years ago

  • Owner set to johnjamesjacoby
  • Resolution set to fixed
  • Status changed from new to closed

In 4987:

When super sticky topics exist in private or hidden forums, they currently always appear in topic-index listings, even when the current user cannot access them.

This changeset adds 'post_parentnot_in' to the super-sticky post query parameters, to exclude topics that are within private/hidden forums the current user cannot access. Fixes #2173.

Last edited 8 years ago by johnjamesjacoby (previous) (diff)
Note: See TracTickets for help on using tickets.