#5598 - Multiple issues and potential privileged content leak in Comcode page searching

This is a spacer post for a website comment topic. The content this topic relates to: #5598 - Multiple issues and potential privileged content leak in Comcode page searching
It seems this happens when pages have the _ prefix to hide them from the sitemap, but should it really exclude them from the Search results?
Hello,

No I don't believe they should be excluded. The underscore is specifically only for hiding a page from the sitemap. If a page should be hidden all together, one would mark validated to off on that page.

I'll look into it, thank you. Could be a bug in v11 as well.

Not sure if the _ prefix is at fault here, as without it I am still getting 0 results from some metatags where there should be quite a few returns.

Some meta tags do return results, but strangely a few of these results have titles which doesn't match the content. Crazy, I know.

Automated response: Multiple issues with searching within Comcode pages

This ended up being multiple issues with the search module / comcode_page hook rather than the tags.

1) The comcode_page hook was marking cached comcode pages as having been searched without actually searching within them for results. This explains why sometimes after searching, if you refresh or go to the next page, you now have fewer results.
2) Search results were excluding pages that began with an underscore. This shouldn't happen; underscore solely controls visibility on the sitemap and everywhere else should use the unvalidated addon for controlling visibility.
3) There were also a couple potential leaks where privileged content a member does not have access to could leak into the search results. This particular issue resulted in me upgrading this to a major bug.

Notice: Those using the nusearch addon will have to update their addon to receive these changes.

Need to check if v11 has the same issue; this patch only applies to v10.

Resolved for v11 in #5910
0 guests and 0 members have recently viewed this.