allowcomments not respected properly
Bug #1095890 reported by
Hugh Davenport
This bug report is a duplicate of:
Bug #1171310: Can bypass comment moderation by editing a comment.
Edit
Remove
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Mahara |
Triaged
|
High
|
Unassigned |
Bug Description
Not sure why, but the function user_comments_
The particular access right i found it on was an "objectionable" type.
Changed in mahara: | |
assignee: | nobody → Son Nguyen (ngson2000) |
status: | Triaged → In Progress |
Changed in mahara: | |
assignee: | Son Nguyen (ngson2000) → nobody |
Changed in mahara: | |
status: | Invalid → Triaged |
milestone: | 1.7.0 → 1.8.0 |
Changed in mahara: | |
assignee: | nobody → Son Nguyen (ngson2000) |
Changed in mahara: | |
milestone: | 1.8.0rc1 → none |
assignee: | Son Nguyen (ngson2000) → nobody |
To post a comment you must log in.
There are two options the function user_comments_ allowed( ) needs to check: allowcomments and approvecomments.
if allowcomments of one access right is true, the user can put comments and if approvecomments of one access right is FALSE given the allowcomments is TRUE then the user can publish his/her comment without the approval of the owner.
I think the function user_comments_ allowed( ) is correct as it needs to check though all access rights for both "allowcomment" and "approvecomment" flags