Private content is also shown. How does it exclude?

Comments

ultraBoy’s picture

What is private content?

introfini’s picture

Maybe is talking about some node types that should be excluded. It would be a nice feature to allow choosing the node types that are exposed.

introfini

pfaocle’s picture

Category: support » bug
Priority: Normal » Critical

No - your query (at least in the version I'm playing around with) is not passed through db_rewrite_sql, meaning that any content that is protected by Drupal's node access using a module like TAC, TAC_LITE, Content/Forum Access etc will still be listed on user profiles. When a visitor who does not have access to view these nodes clicks on an item in the User Content listing, he/she will be presented with an Access Denied page.

I'd say this was a critical bug, as enabling this module on a site with content protected by ANY node access control module will expose listings of private content to anonymous and other non-privileged users.

pomliane’s picture

Status: Active » Closed (won't fix)

This version of Usercontent is not supported anymore. The issue is closed for this reason.
Please upgrade to a supported version and feel free to reopen the issue on the new version if applicable.

This issue has been automagically closed by a script.