View Issue Details

IDProjectCategoryView StatusLast Update
0004765Composrgalleriespublic2022-02-01 02:06
ReporterAdam EdingtonAssigned ToChris Graham 
SeveritySecurity-hole 
Status resolvedResolutionfixed 
Product Version10.0.39 
Fixed in Version10.0.40 
Summary0004765: Gallery items set as Members only outputs thumbnails for Guests
DescriptionIf an item of content is not viewable, the thumbnail shouldn't show?
TagsNo tags attached.
Time estimation (hours)
Sponsorship open

Relationships

related to 0004822 resolvedChris Graham Gallery narrow-in functionality should check permissions 

Activities

admin

2022-01-17 20:18

administrator   ~0007259

Automated response: Gallery thumbnail privacy

We should not display a thumbnail for a gallery derived from some content that is set with some kind of privacy, unless that privacy condition matches.

admin

2022-01-17 20:18

administrator   ~0007260

Fixed in git commit 89b7b5699 (https://gitlab.com/composr-foundation/composr/commit/89b7b5699 - link will become active once code pushed to GitLab)

A hotfix (a TAR of files to upload) has been uploaded to this issue. These files are made to the latest intra-version state (i.e. may roll in earlier fixes too if made to the same files) - so only upload files newer than what you have already. If there are files in a hot-fix that you don't have then they probably relate to addons that you don't have installed and should be skipped. Always take backups of files you are replacing or keep a copy of the manual installer for your version, and only apply fixes you need. These hotfixes are not necessarily reliable or well supported. Not sure how to extract TAR files to your Windows computer? Try 7-zip (http://www.7-zip.org/).

hotfix-4765, 2022-01-17 8pm.tar (54,784 bytes)

Issue History

Date Modified Username Field Change
2022-01-16 07:18 Adam Edington New Issue
2022-01-17 15:40 Adam Edington Summary Gallery items set the Members only output thumbnails for Guests => Gallery items set as Members only outputs thumbnails for Guests
2022-01-17 20:18 Chris Graham View Status public => private
2022-01-28 03:18 Chris Graham View Status private => public
2022-01-29 23:32 Adam Edington Note Revision Dropped: 7333: 0003148
2022-01-31 03:52 Chris Graham Relationship added related to 0004822