Author not anonymised on "Shared with me" page and in "Latest pages" block

Bug #1386010 reported by Kristina Hoeppner on 2014-10-27
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Mahara
High
Robert Lyon
1.10
High
Robert Lyon

Bug Description

Mahara 1.10+

When the "Allow anonymous pages" option is ticked in Config site -> General settings, the author's name still shows up on "Shared with me" (tested on an upgraded Mahara 1.10).

This will also need to be tested on an instance that runs Elasticsearch.

CVE References

The above is for a regular portfolio page.

The author's name still shows up in "latest pages" when it is a group page.

summary: - Author not anonymised on "Shared with me" page
+ Author not anonymised on "Shared with me" page and in "Latest pages"
+ block
Aaron Wells (u-aaronw) on 2014-10-31
information type: Public → Public Security
Changed in mahara:
assignee: nobody → Robert Lyon (robertl-9)
Robert Lyon (robertl-9) wrote :

To test:

1) Set the "Allow anonymous pages" option to on in Config site -> General settings

2) as User A create a page and on the 'edit title and description' tag set the page to be anonymous - then share it with logged in users.

3) as User B view page - should see author as hidden
- check your dashboard latest pages - should see author as hidden (currently not)
- search for page in elasticsearch - should see author as hidden (currently not)
- look at the Portfolio -> shared with me pages - should see author as hidden (currently not)

Robert Lyon (robertl-9) on 2014-11-10
Changed in mahara:
status: Confirmed → In Progress

Reviewed: https://reviews.mahara.org/3954
Committed: http://gitorious.org/mahara/mahara/commit/99e189336e51eeb98c9d05c1ab8dce750b6543bb
Submitter: Son Nguyen (<email address hidden>)
Branch: master

commit 99e189336e51eeb98c9d05c1ab8dce750b6543bb
Author: Robert Lyon <email address hidden>
Date: Mon Nov 10 16:08:24 2014 +1300

Hiding author name when page is anonymous on page lists (Bug 1386010)

Some places that were still showing the author's name:
- in elasticsearch
- on shared with me pages
- in 'latest pages' block on dashboard.

To test: see bug report

Change-Id: I106b7d506c2dc3d104f74ea884ff4285e5856483
Signed-off-by: Robert Lyon <email address hidden>

Son Nguyen (ngson2000) on 2014-11-19
Changed in mahara:
status: In Progress → Fix Committed

Reviewed: https://reviews.mahara.org/3997
Committed: http://gitorious.org/mahara/mahara/commit/4d0c41e7678d1f6f7a7b651f21c07d9d77e80a00
Submitter: Robert Lyon (<email address hidden>)
Branch: 1.10_STABLE

commit 4d0c41e7678d1f6f7a7b651f21c07d9d77e80a00
Author: Robert Lyon <email address hidden>
Date: Mon Nov 10 16:08:24 2014 +1300

Hiding author name when page is anonymous on page lists (Bug 1386010)

Some places that were still showing the author's name:
- in elasticsearch
- on shared with me pages
- in 'latest pages' block on dashboard.

To test: see bug report

Change-Id: I106b7d506c2dc3d104f74ea884ff4285e5856483
Signed-off-by: Robert Lyon <email address hidden>

Son Nguyen (ngson2000) on 2014-11-25
Changed in mahara:
status: Fix Committed → Fix Released
status: Fix Released → Fix Committed
Robert Lyon (robertl-9) on 2015-04-17
Changed in mahara:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  Edit
Everyone can see this security related information.

Other bug subscribers