Come together with the global Drupal community in Rotterdam, 28 Sept – 1 Oct 2026. Sessions, contribution, connection, and Early Bird savings until 8 June.
No - your query (at least in the version I'm playing around with) is not passed through db_rewrite_sql, meaning that any content that is protected by Drupal's node access using a module like TAC, TAC_LITE, Content/Forum Access etc will still be listed on user profiles. When a visitor who does not have access to view these nodes clicks on an item in the User Content listing, he/she will be presented with an Access Denied page.
I'd say this was a critical bug, as enabling this module on a site with content protected by ANY node access control module will expose listings of private content to anonymous and other non-privileged users.
This version of Usercontent is not supported anymore. The issue is closed for this reason.
Please upgrade to a supported version and feel free to reopen the issue on the new version if applicable.
This issue has been automagically closed by a script.
Comments
Comment #1
ultraBoy commentedWhat is private content?
Comment #2
introfini commentedMaybe is talking about some node types that should be excluded. It would be a nice feature to allow choosing the node types that are exposed.
introfini
Comment #3
pfaocleNo - your query (at least in the version I'm playing around with) is not passed through db_rewrite_sql, meaning that any content that is protected by Drupal's node access using a module like TAC, TAC_LITE, Content/Forum Access etc will still be listed on user profiles. When a visitor who does not have access to view these nodes clicks on an item in the User Content listing, he/she will be presented with an Access Denied page.
I'd say this was a critical bug, as enabling this module on a site with content protected by ANY node access control module will expose listings of private content to anonymous and other non-privileged users.
Comment #4
pomliane commentedThis version of Usercontent is not supported anymore. The issue is closed for this reason.
Please upgrade to a supported version and feel free to reopen the issue on the new version if applicable.
This issue has been automagically closed by a script.