Option to Exclude Discussions From RSS Feed

System0

Active member
This is an issue I initially brought up in June 2012. This has already been requested by many other Xenforo members (e.g. here) and I feel that it is a problem that should be resolved as soon as possible.

The Problem

Currently, private discussions are displayed in the forum RSS feed. This is something that Xenforo needs to address as a priority.

It is a security risk. What is the point of a private forum if the content can be seen via the RSS feed?

One of the main uses of the RSS feed is to notify followers of new threads on social media services such as Facebook and Twitter. Even if a member does not have permission to view a thread , they will still be able to view the thread title and the beginning of the discussion via RSS or via their social media account.

One of the most common uses of private discussion rooms is a private room for staff and moderators. If a moderator created a thread about whether a member should be labelled as abusive or as a spammer, the title of the thread could be seen as everyone. That could cause a lot of problems.

Currently, the only way to remove private discussions from the RSS feed is to remove the forum room from the new posts list via the "Forum Options" tab (i.e. uncheck the option that says: Include threads from this forum when users click "New Posts"). This is, of course, less than ideal.

I have a private discussion room for moderators and another private discussion room for premium members of my forum. I am happy to remove moderator discussions from the new posts lists. That is not a huge inconvenience. However, I do not want to disable new post notifications from the premium members room as it would decrease activity in those discussions.

My Suggestion

We need an option on a room by room level to remove discussions from the RSS feed. This should be a separate option from removing discussions from the "New Posts" page.

Preferably, if a discussion room is set to private, the default configuration should be that discussions are not displayed in the RSS feed but are displayed in the "New Posts" page to authorised members.

I have seen a couple of template fixes for this suggested in the forums. However, this is something I strongly believe should be incorporated into the core so that we do not need to apply manual edits every time a discussion room is set as private.

Kevin
 
Upvote 0
Currently, private discussions are displayed in the forum RSS feed. This is something that Xenforo needs to address as a priority.

It is a security risk. What is the point of a private forum if the content can be seen via the RSS feed?
Content from private forums can only be seen in the RSS feed if you are using an RSS reader that supports RSS authentication and you are authenticated against that feed (ie you are logged into your forum via the reader) and you have the permissions to view those private forums.

If you cannot view those forums, you will not see the content of these in the RSS feed. To see this, log out of your forum and then click on the RSS icon. You won't find any private forum content in what you see.
 
Currently, private discussions are displayed in the forum RSS feed. This is something that Xenforo needs to address as a priority.

It is a security risk. What is the point of a private forum if the content can be seen via the RSS feed?
As clarified above by Martok, this is incorrect.
 
Back
Top Bottom