View Full Version : [Not Fixing] 2.2.9 search question
telc
Sat 24th May '03, 2:36am
On 2.2.9 I did on my forums for,
This is the results page I got it has "6" results.
http://forums.clubrsx.com/search.php?action=showresults&searchid=672118&sortby=lastpost&sortorder=descending
But if "You" click on that link you will see thousands of results, becuase its ignoring the "username" part of the search and it is just doing a search for "pedal".
If I logout and click the link I get thousands of results, if i log back in and click it I get the "6" results.
Is this a security feature or a bug?
Steve Machol
Sat 24th May '03, 12:13pm
I ran a new search and got exactly 6 hits.
http://forums.clubrsx.com/search.php?action=showresults&searchid=672580&sortby=lastpost&sortorder=descending
telc
Sat 24th May '03, 12:46pm
I ran a new search and got exactly 6 hits.
http://forums.clubrsx.com/search.php?action=showresults&searchid=672580&sortby=lastpost&sortorder=descending
Thats what I am a saying, If I click the link you just posted I get back like 1200 results becaue its ignoring the "username" its just doing a search for "pedal". If I click on the link I posted I get back 6 results. But if I log out of clubrsx and click on the link I posted I get 1200 results also.
Steve Machol
Sat 24th May '03, 12:50pm
Oh, I see. Can't say I've ever heard of this one before. Have you installed any hacks?
telc
Sat 24th May '03, 1:10pm
Oh, I see. Can't say I've ever heard of this one before. Have you installed any hacks?
no, I notice it on other boards too.
Steve Machol
Sat 24th May '03, 1:52pm
Sorry I can't duplicate this problem on either on my 2 forums. Please provide an example of another forum that does this.
telc
Sat 24th May '03, 6:05pm
Sorry I can't duplicate this problem on either on my 2 forums. Please provide an example of another forum that does this.
Here is a search I did at vbulletin.org:
Keyword: archive
Username: muxx
http://www.vbulletin.org/forum/search.php?s=&action=showresults&searchid=514110&sortby=lastpost&sortorder=descending
If I click that link I get back "one" result. But If I send that link to friends I they get back many results, becuase its ignoring the "username". If I log myself out of "vbulletin.org" and click the link I get back many results also. But if I log back in and click the link I get back the "one" result.
Steve Machol
Sat 24th May '03, 6:29pm
Hmmm...since vB.org is running 2.3.0 I'm going to move this to Bugs so a Dev can check into this.
Scott MacVicar
Mon 9th Jun '03, 4:52am
This bug is caused by the search being run by a different user than the original.
For security purposes the search is re-run. The search user isn't a value stored in the database so isn't passed on when the search is re-run.
As vB3 is due relatively soon and it would involve adding another column to the table we have decided not to fix this bug in the v2 version.
telc
Mon 9th Jun '03, 10:48am
This bug is caused by the search being run by a different user than the original.
For security purposes the search is re-run. The search user isn't a value stored in the database so isn't passed on when the search is re-run.
As vB3 is due relatively soon and it would involve adding another column to the table we have decided not to fix this bug in the v2 version.
When you say "search user" isn't stored. Are you refering to the user who originaly executed the search or the username that was typed in the "username" field on the search page.
Because the userrid that is typed into the username field on the search page is stored in the db and the username who originaly executed the search are both stored in 2.2.9. I just ran a search and checked the database.
vBulletin® v3.8.0 Beta 1, Copyright ©2000-2008, Jelsoft Enterprises Ltd.