Closed (fixed)
Project:
Drupal core
Version:
4.6.0
Component:
profile.module
Priority:
Critical
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
26 Nov 2004 at 23:14 UTC
Updated:
8 Oct 2005 at 07:20 UTC
If an anonymous user enters the following:
{mysite.com}/user/{any user number}
the entire profile listing is obtained for all fields except those marked as private. The only choices for privacy in profile.module are either private or two variations of public (shown in member list or not ... but always in profile list). Seems like there should be a control to specify the roles that can see the info for each field rather than merely public versus private.
I've marked this as a bug, and as critical because I'm guessing a lot of users won't realize the exposure of this information.
gil
Comments
Comment #1
Dublin Drupaller commentedbumping this...
Comment #2
killes@www.drop.org commentedDuplicate http://drupal.org/node/1137
Comment #3
Dublin Drupaller commentedthat duplicate link you posted goes to a patch for cvs...is there a patch for 4.5 as the original post was looking for ?
Or does the CVS patch apply?
Jason
Comment #4
killes@www.drop.org commentedOne of the older patches in that issue might apply to 4.5.
Comment #5
Dublin Drupaller commentedHi Killes,
Have trawled through those CSV patches and I can't make out what would apply and what wouldn't - I'm a newbie and was hoping I could spot something simple from the patches that could be applied to 4.5.
Any other tips or guidance. I would like to help, but, my skills are limited.
Jason
Comment #6
Dublin Drupaller commentedbumping this one...
Comment #7
killes@www.drop.org commentedJust try to apply one after another.
This one moght apply to 4.5.
http://drupal.org/files/issues/access_users_perm.patch
Comment #8
Capnj commentedIs there a 4.5.1 version of this patch? Or can someone far more knowledgeable than I do a user.module and profile.module patched with this access control?
gil
Comment #9
Dublin Drupaller commentedHere's a fix I have come up with that works well with drupal 4.5.0.
http://drupal.org/node/13669#comment-22804
Hope it's of use to others...
Jason
Comment #10
Capnj commentedJason's fix works very nicely.
Thanks, Jason!
gil
Comment #11
Capnj commentedMarking this as fixed because at least for 4.6.x it's fixed.
Comment #12
(not verified) commentedComment #13
(not verified) commentedComment #14
(not verified) commentedComment #15
(not verified) commentedComment #16
(not verified) commented