#5446 - Private topics get leaked when set to receive notifications for all forum topic activity

  • By
  • Added
  • 7 views
Identifier #5446
Issue type Major issue (breaks an entire feature)
Title Private topics get leaked when set to receive notifications for all forum topic activity
Status Completed
Tags

Type: Legal compliance / Privacy (custom)

Handling member PDStig
Version 10.0.43
Addon core_cns
Description Private topics will get leaked to members who have their notifications set to receive notifications for all forum topic activity.

This includes the title and URL of the PT. It also includes system messages, such as when someone is invited to the topic. It does not include the first post in the PT. I am not sure yet if it includes any further posts by members.

This is a high priority bug as it is a privacy risk.
Steps to reproduce

Funded? No
Commits

Fixed MANTIS-5446 (Leaked PTs to members monitoring all topic activity) (9302069d) · Commits · Composr ecosystem / Composr · GitLab

The system will post a comment when this issue is modified (e.g., status changes). To be notified of this, click "Enable comment notifications".

Rating

Unrated