Project

General

Profile

Actions

Bug #185

closed

Private Group Info/Documents on Activity Stream

Added by Matt Gold about 14 years ago. Updated almost 14 years ago.

Status:
Resolved
Priority name:
Immediate
Assignee:
Category name:
BuddyPress (misc)
Target version:
-
Start date:
2010-03-18
Due date:
% Done:

0%

Estimated time:
Deployment actions:

Description

Just noticed that documents posted to private Groups through the Group Documents plugin are publicly viewable and downloadable even to non-logged-in users. Yikes.

See http://commons.gc.cuny.edu/members/sbrier/

Actions #1

Updated by Boone Gorges about 14 years ago

  • Status changed from Assigned to Reporter Feedback

I tried tracking down the real root of the problem but I had a hard time finding it. I fear that it might have something to do with the way that the group document plugin interacts with BP 1.1.3.

Since we're upgrading soon, I have taken the stopgap measure of disabling activity stream posts altogether for documents posted to private and hidden groups. I'll have another look after the upgrade to see if the problem fixes itself.

Actions #2

Updated by Matt Gold about 14 years ago

Great. Thanks for taking care of this so quickly, Boone. Wish we had that "hold" category going . . . maybe we should just leave it on "feedback" in the meantime?

Actions #3

Updated by Boone Gorges about 14 years ago

Fine, leave it on feedback.

Actions #4

Updated by Boone Gorges almost 14 years ago

  • Status changed from Reporter Feedback to Resolved

Haven't heard back so I'll assume it's working fine.

Actions

Also available in: Atom PDF