Sim
Well-known member
We have an issue on ZooChat where members and guests can view deleted media using the /full url
I checked on my other sites running XF1.5/MG1.1 and my dev server and also on my XF2 dev server and they all work as expected (soft deleted photos are not visible to members/guests) - so there's something about how ZooChat is set up which is different.
The main difference between all these servers is that ZooChat imported its media content from PhotoPost, while none of the other sites I've tested did.
EDIT: I just tested another site which had media imported from PhotoPost and this one works as expected - so I'm not sure its directly related to the import? Unless there were some permissions imported as well during the import process which were unique to ZooChat?
So otherwise, there is something specific about the configuration on ZooChat which causes this issue, but I can't work out which setting is causing this behaviour.
Example: this following image has been (soft) deleted - media link: https://www.zoochat.com/community/media/test.401362/), and yet the image itself is still visible to guests (and members) using the direct URL - "full" image url: https://www.zoochat.com/community/media/test.401362/full
I checked on my other sites running XF1.5/MG1.1 and my dev server and also on my XF2 dev server and they all work as expected (soft deleted photos are not visible to members/guests) - so there's something about how ZooChat is set up which is different.
The main difference between all these servers is that ZooChat imported its media content from PhotoPost, while none of the other sites I've tested did.
EDIT: I just tested another site which had media imported from PhotoPost and this one works as expected - so I'm not sure its directly related to the import? Unless there were some permissions imported as well during the import process which were unique to ZooChat?
So otherwise, there is something specific about the configuration on ZooChat which causes this issue, but I can't work out which setting is causing this behaviour.
Example: this following image has been (soft) deleted - media link: https://www.zoochat.com/community/media/test.401362/), and yet the image itself is still visible to guests (and members) using the direct URL - "full" image url: https://www.zoochat.com/community/media/test.401362/full