•  · 5 friends

Secret group breach

1. User "58" (let's name him so) creates Secret Group with no members, except himself

2. User "58" creates post in Secret Group and upload picture

3. User "207" CAN SEE this post in Public Fed, can scroll pictures (if some uploaded) in the feed.Β 

User "207" can not enter the group. But CAN SEE it in public feed and can comment on it there - it is definately a bug.


NB- the same is with Albums and Discussions posted in Secret Group


Fix it, please.



πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
  • 1018
  • More
Attachments
Replies (18)
    • the weekly bump

      πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
      • Hi Vavlion!

        Sent you a message.

        With the best regards, Leonid

        πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
        • πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
          • Thanx, Alex:) Let me just be sure: it's not about Timeline posts only (as you say in GitHub explanation), it's about Discussion/Album etc, posted to Secret Group through Discussion/Album Visibility option.Β 

            πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
            • Yes, it for all modules, not only for direct posts into Timeline.

              πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
              • Alex, it still problematic, don't know if it depends on upgrading, but for sure after it, so....

                check, please invitation to secret group, there is no option to enter it

                After updating three .php files from GitHub feed behaviore looks fine but :

                1. User A opens Secret Group

                2. User A sends invitation to user B

                3. User B get the email and click enclosed link to group

                4. User B can not enter becouse of "Access denied. This is private content."

                Thanx in advance

                πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
                • Hy guys, still not working:

                  1. User A opens secret group (pic. secret 11)

                  2. User A can't see this group in Groups List (New Section) (despite it's HIS group and he IS Meber AND Admin of this group) (pic. secret 22)

                  3. User A can see thes group in Manage section of Group List (pic. secret 33)

                  4. User A creates Discussion in his Secret Group

                  5. User B - no member, of course - still can with link to see lest of Discussions (pic. secret 44)

                  6. Needs to say that Albums and Pools user B can not see, wich is very ok. (pic. secret 55)

                  7. NB : Β #5 - is the problem of Closed Groups too.


                  Guys, fix please pos. #2 and #5.



                  πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
                  • Alex has only mentioned that an issue has been created and listed as a bug in RC9. I don't see anywhere it being marked as fixed. I would give it time as I am guessing it will be fixed for the upcoming full version release.

                    πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
                    • look at final line in GitHub : AntonLV closed this 4 days ago.Β 

                      there are fixed files and I've installed them to check,

                      πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
                      • I see where it was labeled as closed since it was added to the list of bugs that need to be fixed. I don't think it's been resolved.

                        πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
                        • Thank you for checking, but it maybe other related fixes in other tickets, please try to reproduce on http://ci.una.io/test/

                          PS: PM me for studio access

                          πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
                          • trying to register

                            gettingΒ 

                            This page isn’t working

                            ci.una.ioΒ is currently unable to handle this request.

                            HTTP ERROR 500

                            πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
                            • Β JeremyΒ  IMHO, closed - means solved, bug - is a category.

                              πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
                              • I understand. Don't think that's the case though.

                                πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
                                • Did this get resolved? Β I am on 11.0.3 and I just had a user see a post I made in a secret group. Β They also liked the post. Β Alex T⚜️ LeonidSΒ 

                                  πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
                                  • Hello mrochek !

                                    This problem has been fixed a long time ago and I can't reproduce it from my side. Even if both users are friends. Only if both members are admins - they may see the timeline posts about the group's creation and new posts there.

                                    πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
                                    • LeonidS see my comment in the thread "Closed group privacy settings" I posted screenshots if the issue

                                      πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
                                      • πŸ’“0 πŸ˜†0 😲0 πŸ˜₯0 😠0 0
                                        Not logged in users can't 'Comments Post'.
                                        8
                                        3
                                        2
                                        3
                                        3
                                        Added:
                                        Category:

                                        UNA - Network Infrastructure for Communities

                                        Close