1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Fixed Moderated Profile Posts shown to every visitor.

Discussion in 'Resolved Bug Reports' started by Shadab, Feb 17, 2011.

  1. Shadab

    Shadab Well-Known Member

    In, XenForo_Model_ProfilePost::getPermissionBasedProfilePostConditions()

    		else if ($user['user_id'])
    			$viewModerated = $user['user_id'];
    $user should be $viewingUser instead.
  2. Mike

    Mike XenForo Developer Staff Member

    I'm pretty sure that would only show moderated profile posts (status updates) on the user's own profile, so it's not every profile post, but fixed nonetheless. Thanks. :)
  3. Shadab

    Shadab Well-Known Member

    Thanks for the fix!

    Btw, it did bypass the viewModerated permission on all profiles. User ID of the profile being viewed was returned, so messages were fetched from the profile owner's perspective. I only noticed this recently when unapproved status updates on an Admin account didn't go away even after I logged out. :p
  4. Mike

    Mike XenForo Developer Staff Member

    Yeah, I just meant that if I wrote on your profile and it wasn't approved, guests couldn't see it. Though if I wrote on my own profile (status update), then people could indeed see it while it wasn't approved.

Share This Page