Logged Out
Create an Account
Login:
Password:

Forgot your password?
Forum Permission Bug


Back to the Tickets List

Forum Permission Bug
Creator ron_post
Public or Private Public
Private tickets are only accessible to you and to DKPSystem.com staff
Public Tickets are visible to everyone)
Status Closed
Type Bug
Section of the Site Forum
Urgency (1 votes)
Rating (1 votes)
Description:
If you view a thread using "viewthread.php", the top header area (with title, primary/secondary tags, and so on) will contain "[Post Reply]", even if you don't have permission to post in that tag (and using it will allow you to post a reply). The default forum view uses "oldviewthread.php", and doesn't have this problem.

While this primarily shows up through the "Popular Threads" list (which has links using viewthread.php), any user can simply change their url on a viewed thread to remove the "old" part, and thus get posting privileges on tags they only have viewing permission for.

Edit: after some testing, it seems that this isn't a general problem - I was not able to handcraft a post to a tag I didn't have permission to post to. For some reason, the same testing is not taking place on replies, that is being performed on thread starting posts.
Official DKPSystem.com Comments
No official comments yet

User-Submitted Comments
These posts are also available on the forum with more features. This page is intentional simplified

View this info on the forum
[You must be logged in to post comments]
5759 days ago
Chops Said:
Fixed. Thank you for the notification.
[You must be logged in to reply]