Direct-link blog content not secured

This is the place to report bugs and get support. When posting in this forum, please always provide as much detail as possible.

Please do not report problems with a custom build or custom code in this forum. If you are producing your own build from the source code and have problems or questions, ask in the developer forum, do not report it as a bug.

This is the place to report bugs and get support

When posting in this forum, please try to provide as many relevant details as possible. Particularly the following:

  • What operating system were you running when the bug appeared?
  • What database platform is your site using?
  • What version of mojoPortal are you running?
  • What version of .NET do you use?
  • What steps are necessary to reproduce the issue? Compare expected results vs actual results.
Please do not report problems with a custom build or custom code in this forum. If you are producing your own build from the source code and have problems or questions, ask in the developer forum.
This thread is closed to new posts. You must sign in to post in the forums.
4/13/2010 11:33:12 AM
Gravatar
Total Posts 13

Direct-link blog content not secured

Hello,

I believe I found a security problem, but it could be a configuration issue?

I have a blog feature on the homepage - The security is restricted to certain roles.  Also, the blog feature is set to be hidden from anonymous guests.

The blog is properly hidden from view on the home-page, but if I know the URL of the blog entry directly, I can browse to it anonymously and view the entire entry.

??

4/13/2010 12:38:42 PM
Gravatar
Total Posts 18439

Re: Direct-link blog content not secured

Hi Jason,

Thanks for the bug report, only wish I had known in time for this release. I've fixed it but it will have to wait for the next release.

Best,

Joe

4/13/2010 12:46:08 PM
Gravatar
Total Posts 13

Re: Direct-link blog content not secured

I imagine this is just a single DLL that needs redeploying.  Can you just slip me that one dll?

Note: I wouldn't "expect" (it's free, what's expect??) anyway, I wouldn't expect such a thing to be supported.

4/13/2010 1:27:42 PM
Gravatar
Total Posts 18439

Re: Direct-link blog content not secured

I just patched the 2.3.4.2 release with this fix. All you need is the new mojoPortal.Features.UI.dll and mojoPortal.Web.dll

Hope it helps,

Joe

4/13/2010 1:33:59 PM
Gravatar
Total Posts 13

Re: Direct-link blog content not secured

Nice!  Thanks Joe.  Works great!

You must sign in to post in the forums. This thread is closed to new posts.