Logged Out
Create an Account
Login:
Password:

Forgot your password?
Forum RSS insecurity

Forum RSS insecurity
[Back to Index]
Thread Tags
Primary: [Tickets]
Secondary: None

Forum RSS insecurity
Go To This Ticket's Page
Creator ron_post
Public or Private Public
Private tickets are only accessible to you and to DKPSystem.com staff
Public Tickets are visible to everyone)
Status Closed
Type Bug
Section of the Site Forum
Urgency (0 votes)
Rating (0 votes)
Description:
The forum security features (restricting what posts users have access to, including what non-logged in users can see) do not prevent users (and guests) from using the Forum RSS feed to get titles to all posts. This can be somewhat problematic if you tend to use descriptive titles.

Of course, the posts themselves are still restricted - clicking on the link will only take you to the forum, not the post.
Official DKPSystem.com Comments
No official comments yet
Thank you, a fix for this should be deployed soon.


--
It's all in the reflexes.
The fix for this has been deployed, along with a couple simple aesthetic changes (like showing Thread Tag for posts).


--
It's all in the reflexes.
Thanks for the fix!

Of course, now it appears that even if you are logged in, you only get the guest viewable posts in the rss feed (I know, no satisfying some people ).
Quote by ron_post
Thanks for the fix!

Of course, now it appears that even if you are logged in, you only get the guest viewable posts in the rss feed (I know, no satisfying some people ).


For that, make sure you use the "Private RSS Feed"
(link found in the logged in box)

The public RSS feed should ALWAYS be just the publicly available stuff, while the private RSS feed is specific to you.


--
It's all in the reflexes.


[Back to Index]