Affiliates can see members of communities they are not in

Bug #594131 reported by Jim B. Glenn
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
KARL3
Fix Released
High
Chris Rossi

Bug Description

I just found a security-related bug. I just logged in as my Affiliate
account (https://karl.soros.org/profiles/nkatinborland/), which is a
member of 2 communities, with just a few other users. However, when I
click on the People tab, 195 users show up. If I click on user, who is
not a member of one of the two communities, then I get a forbidden
message, but affiliates should only see people in their communities in
the first place. I have tested with several other Affiliate accounts
with the same result. Please look into why Affiliate users are seeing
non-members of their communities.

Thanks,

Nat

Tags: karl-support
Revision history for this message
Jim B. Glenn (jimbglenn) wrote :
tags: added: karl-support
Revision history for this message
Paul Everitt (paul-agendaless) wrote :

Hi Chris. I'm going to mark this as "High" just for the part about investigation. Once we learn more about it, we might change it to medium.

Changed in karl3:
importance: Undecided → High
assignee: nobody → Chris Rossi (chris-archimedeanco)
milestone: none → m42
Changed in karl3:
status: New → In Progress
Revision history for this message
Chris Rossi (chris-archimedeanco) wrote :

This was caused by profiles added via GSA getting improperly indexed. I have fixed this bug and created an evolve script to reindex the people directory after the fix is applied.

Changed in karl3:
status: In Progress → Fix Committed
Revision history for this message
JimPGlenn (jpglenn09) wrote :

fixed

Changed in karl3:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.