Jump to content

RSS Feeds are including topics from private clubs!


WebCMS

Recommended Posts

I have a private club meant for moderators only but the new RSS feed I created is listing topics from this private club. This is a serious security issue. The new feed I created does not have any options for Clubs.

Is there a way to disable the Default RSS feed (Discussion Latest Topics feed)?

Please advise...

Edited by WebCMS
Link to comment
Share on other sites

3 hours ago, teraßyte said:

Unless you share the "XXX Latest Topics" feed link, nobody can access it. It contains your member ID and a unique key for your account.

Since it's a private club, people without access to it will never even see the link.

You are right. I did not notice the member ID unique key in the URL.

Thanks!

Link to comment
Share on other sites

I see that each forum and club has it own RSS Feed in the icon menu at bottom right. When I visit the private Moderators club, there is an RSS Feed for the private club. How do I disable the RSS Feed for Moderators only as it can contain private topics if shared inadvertently?

I unchecked Moderators group in the new RSS Feed's Settings but when visiting each forum/club, there still appears an RSS Feed in the footer for the visited forum/club and this happens even for the private Moderator's club - the URL with the member ID private key.

It is ok if moderators don't have access to RSS Feeds but not sure how disable RSS Feeds for moderators.

Link to comment
Share on other sites

15 hours ago, Marc Stridgen said:

There would be no way in which to do that unfortunately. Feel free to post that up within the feedback forum if its something you would like to see in the future.

In a case where a mod leaves the forum, the mod's personal URL to the RSS Feed of the private Mod club remains the same which is a concern. Now we end up deactivating the account and create a new mod account for the new person. I'll submit a suggestion.

Link to comment
Share on other sites

6 hours ago, WebCMS said:

In a case where a mod leaves the forum, the mod's personal URL to the RSS Feed of the private Mod club remains the same which is a concern. Now we end up deactivating the account and create a new mod account for the new person. I'll submit a suggestion.

While it remains the same, it will not have the same permissions. It will have the permissions of that member. 

Link to comment
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...