Can bypass comment moderation by editing a comment
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Mahara |
Fix Released
|
High
|
Robert Lyon | ||
1.5 |
Fix Released
|
High
|
Robert Lyon | ||
1.6 |
Fix Released
|
High
|
Robert Lyon | ||
1.7 |
Fix Released
|
High
|
Robert Lyon |
Bug Description
A user can make their comments on a page public, even if the page is set to require comment moderation, if they create the comment as a private comment and then change its status to public while editing it.
To replicate:
1. Create a Page for User 1
2. Make the page accessible to the public, and activate comments & comment moderation for the page (this is all under the Sharing tab)
3. Log in as User 2
4. Place a comment on the Page, making sure to untick the "Make public" box so that the comment is private.
5. Click the "edit" icon next to the newly created comment.
6. On the edit page, tick the "Make public" box, and click Save.
Expected result: The comment's status should be "This comment is private | You have requested that this comment be made public"; and it shouldn't become public until approved by User 1
Actual result: The comment becomes public immediately after you click Save on the Edit page.
Changed in mahara: | |
assignee: | nobody → Robert Lyon (robertl-9) |
Changed in mahara: | |
status: | Triaged → In Progress |
Changed in mahara: | |
status: | In Progress → Fix Committed |
Changed in mahara: | |
milestone: | 1.8rc1 → 1.8.0 |
Changed in mahara: | |
status: | Fix Committed → Fix Released |
Whoops, I was logged in as the "Mahara Bot" user doing some work on the Translations set up earlier today, and it looks like I forgot to log out before logging this bug. :)