Denying access to forum names through direct url's

keppi - May 21, 2008 - 11:26
Project:Taxonomy Access Control
Version:6.x-1.x-dev
Component:Code
Category:feature request
Priority:normal
Assigned:Unassigned
Status:needs review
Description

Hi,

I've noticed that a user who has TAC settings denying access to forums, can still view the name of any forum by using the direct clean url's to them. I.e. http://example.com/forum/2

This might mean leaking bits of information to users it isn't meant for. Probably not a big issue for most people, but would be nice if it can be fixed.

#1

Markpanzee - August 14, 2008 - 21:42

I've had the same issue - I dealt with it by also adding on the Forum Access Control module. I don't think TAC can hide this because the main forum pages are not nodes, and I don't know of any way of supplying a forum page with a taxonomy term. It would be nice though if I didn't have to use an additional module just for this one feature. Does anyone know a simpler way?

#2

phKU - December 9, 2008 - 13:01

subscribing…

#3

John Morahan - June 17, 2009 - 13:47
Version:5.x-1.1» 6.x-1.x-dev
Status:active» needs review
AttachmentSize
taxonomy_access-forum.patch 878 bytes
 
 

Drupal is a registered trademark of Dries Buytaert.