Jump to content

Users can edit posts after the post has been hidden


Go to solution Solved by Marc,

Recommended Posts

Posted

There's no check that the user has permission to see the post being edited, so it's possible to edit a post after it has already been hidden.

To reproduce:

  • Post in a topic
  • Start editing that post
  • Moderator hides the post
  • Submit the edit
  • Edit goes through successfully

It's not so bad in that repro, because they must have had it open already, but it's not great if the user constructs the calls manually to both load the current version of the post, and make changes to it.

Posted

Thank you for bringing this issue to our attention! I can confirm this should be further reviewed and I have logged an internal bug report for our development team to investigate and address as necessary, in a future maintenance release.

 

  • 3 weeks later...
  • Solution
Posted

This issue has been resolved in our recently released 4.7.9 version. Please upgrade if you are seeing this issue, and let us know if you see any further issues.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...