? .cvsignore
? fix_private_files.patch
Index: privatemsg_attachments/privatemsg_attachments.module
===================================================================
RCS file: /cvs/drupal/contributions/modules/privatemsg/privatemsg_attachments/privatemsg_attachments.module,v
retrieving revision 1.7
diff -u -p -r1.7 privatemsg_attachments.module
--- privatemsg_attachments/privatemsg_attachments.module	8 Sep 2010 21:59:11 -0000	1.7
+++ privatemsg_attachments/privatemsg_attachments.module	24 Nov 2010 20:43:44 -0000
@@ -400,10 +400,12 @@ function phptemplate_privatemsg_list_fie
  * Implements hook_file_download().
  */
 function privatemsg_attachments_file_download($filepath) {
+  global $user;
   $filepath = file_create_path($filepath);
   $result = db_query("SELECT f.*, pma.mid FROM {files} f INNER JOIN {pm_attachments} pma ON f.fid = pma.fid WHERE filepath = '%s'", $filepath);
   if ($file = db_fetch_object($result)) {
-    if (user_access('view private message attachments') && privatemsg_message_load($file->mid)) {
+    // Try to load the message, pass user object to check recipient status.
+    if (user_access('view private message attachments') && privatemsg_message_load($file->mid, $user)) {
       return array(
         'Content-Type: ' . $file->filemime,
         'Content-Length: ' . $file->filesize,
Index: privatemsg_attachments/privatemsg_attachments.test
===================================================================
RCS file: /cvs/drupal/contributions/modules/privatemsg/privatemsg_attachments/privatemsg_attachments.test,v
retrieving revision 1.3
diff -u -p -r1.3 privatemsg_attachments.test
--- privatemsg_attachments/privatemsg_attachments.test	22 Oct 2010 08:47:35 -0000	1.3
+++ privatemsg_attachments/privatemsg_attachments.test	24 Nov 2010 20:43:44 -0000
@@ -26,6 +26,14 @@ class PrivatemsgAttachmentsTestCase exte
   function testPrivateDownloads() {
     variable_set('file_downloads', FILE_DOWNLOADS_PRIVATE);
     $this->testPublicDownloads();
+
+    // Make sure that other users can't view the private file.
+    $file_url = $this->getUrl();
+    $other_user = $this->drupalCreateUser(array('read privatemsg', 'view private message attachments'));
+    $this->drupalLogin($other_user);
+
+    $this->drupalGet($file_url);
+    $this->assertResponse(403, t('Access to private attachment denied for other user.'));
   }
 
   /**
