#6009 UNMODERATED_POST allows edits to anonymous posted comments [ss3211]

unreleased
open
nobody
General
nobody
2015-02-19
2013-03-26
Chris Tsai
No

[forge:site-support:#3211]

Also, another problem I found with my settings that allow anonymous users is that the forum allows any anonymous user to edit any other user's messages. There is no cookie check to prevent an anonymous user from editing a message posted by another anonymous user.

I've reproduced this here: https://sourceforge.net/p/strawhat/discussion/nearend/thread/a3099582/

The initial post and first reply were moderated posts, the last one was added after I added *anonymous to UNMODERATED_POST. When viewing that page anonymously (or with any user account), you should see an edit link on the last post, but not the others.

If a cookie check isn't feasible, I personally think that removing the ability for anonymous to edit would be fine.

Discussion


Log in to post a comment.