-
-
Notifications
You must be signed in to change notification settings - Fork 830
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
"Mentioned by" on posts sometimes leaks hidden posts #3846
Comments
@matteocontrini could you provide |
I just tried replicating this: https://discuss.flarum.org/d/33052-mentioned-by ![]() incognito: ![]() I can't replicate it, so might be an extension. Can you either: a) disable extensions one by one to see if this re-occurs or b) provide a composer.json so we can attempt to reproduce locally? |
@matteocontrini if you upgrade to the latest |
@imorland that was it, fixed, thank you everyone! |
Excellent news @matteocontrini - thanks for confirming :) |
Current Behavior
When a post (A) is mentioned by another post (B), and post B is hidden, the "mentioned by" section at the bottom of post A shows the preview of post B, even if the post is hidden and the user/actor is not authorized to see hidden posts.
Note that this doesn't happen if flarum/issue-archive#76 gets in the way: in that case, the mention is deleted from the db and thus post A doesn't show post B as a reply to it.
If you're wondering why this issue actually exists, since flarum/issue-archive#76 should make it impossible: I have no idea, I just know for sure that it happens even on the latest stable version, after seeing multiple occurences of that on a forum I manage (see example below).
Steps to Reproduce
Theoretically, these would be the steps that reproduce the issue:
The post by
Joanlui
in the screenshot above is actually hidden. (Ignore the gap between the two posts, that's a placeholder for ads.)What I see as an admin:
Link to that post, if it helps: https://forum.fibra.click/d/25781-bolletta-luce-e-gas-cosa-scelgo/8274
Expected Behavior
Hidden posts should never be shown to standard users.
Screenshots
No response
Environment
Output of
php flarum info
I can provide it if relevant.
Possible Solution
No response
Additional Context
No response
The text was updated successfully, but these errors were encountered: