Registered user's nicknames protection missing

petiar - April 7, 2008 - 21:44
Project:Guestbook
Version:6.x-2.x-dev
Component:Code
Category:feature request
Priority:normal
Assigned:Unassigned
Status:needs review
Description

Hi,

thanks for great module. RC1 looks fine apart from the fact that anonymous can use the nickname of any of the registered users. I think this should not be allowed, what do you think?

If you are aware of this or even working on this, accept my apologies and ignore/delete this issue.

Thanks,
Petiar.

#1

sun - April 22, 2008 - 19:34
Component:User interface» Code

How does Drupal core handle this? Patches are welcome.

#2

petiar - April 25, 2008 - 10:20

I have no idea how Drupal core handle this, do you think it is its responsibility?

However, I'll have a look into the Guestbook code and see what can I do - it should not be complicated to implement this check.

Thanks,
Peter.

#3

sun - April 25, 2008 - 17:13

Please make sure that Comment module in Drupal core does not already implement a working solution. If it does, we'll probably fork that functionality directly from there, so any improvements to Comment module's functionality can be added to Guestbook's.

#4

sun - May 13, 2008 - 23:45
Version:6.x-1.0-rc1» 6.x-1.x-dev
Category:bug report» feature request

Reclassifying.

#5

sun - September 9, 2008 - 18:28
Version:6.x-1.x-dev» 6.x-2.x-dev
Status:active» needs review

Attach patch is against CVS HEAD (6.x-2.x). Please test.

AttachmentSize
guestbook.anonname.patch 1 KB
 
 

Drupal is a registered trademark of Dries Buytaert.