View Issue Details

IDProjectCategoryView StatusLast Update
0001255HTML & PERLBug Report - Interfacepublic2008-08-29 23:41
ReporterNyxx Assigned Topelican  
PrioritynormalSeverityminorReproducibilityalways
Status resolvedResolutionfixed 
Summary0001255: "Latest" informations for the public is unfiltered
DescriptionUnder the "Latest" tab a guest can see informations where I denied the access for the public in my profile.

Profile settings:
- see my userpage: everyone
- see my wishlist: no one
- see my votes: no one
- see viewed info: members and buddies
(- see state info: only with password)

With these settings I expect that a guest cannot see these three "latest" lists:
 - Watched
 - Anime votes
 - Wish list entries

But the user can still see all latest informations. This is bad in terms of privacy.

Workaround (from exp):
Disable the access to your userpage for everyone. Set "see my userpage" to something less than "everyone".
Steps To Reproduce- log in with your anidb user
- in your profile page set "see my userpage" to "everyone"
- log out
- open your userpage (without being logged in!) and click on "Latest", or use this link to open it directly:
   http://anidb.net/perl-bin/animedb.pl?uid=123456789&show=userpage&do=latest
  Where "123456789" is your userid.
TagsNo tags attached.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2008-08-25 23:58 Nyxx New Issue
2008-08-29 23:41 antennen Assigned To => pelican
2008-08-29 23:41 antennen Status new => resolved
2008-08-29 23:41 antennen Resolution open => fixed