Members are able to view private profile albums

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • flashgordon
    Senior Member
    • Sep 2006
    • 206
    • 3.5.x

    Members are able to view private profile albums

    It has come to my attention that some members of my forum can see the private albums of some other members, even if they are not on the friends list. They are not even "buddies". The accounts are totally unrelated.
    I have checked it myself, using the account of one of the members, and the private albums and the private album pictures are accessible.

    How can I fix this? It is causing big problems on my forum.
    I already tried to turn off all the plugins (with disabled_hooks in config.php) and the problem persists.
    Last edited by flashgordon; Sat 17 Sep '11, 11:49pm.
  • flashgordon
    Senior Member
    • Sep 2006
    • 206
    • 3.5.x

    #2
    This is very strange. It's only happening to some members, and I cannot reproduce the error.
    As I said, a member who is not on the friends list can view private pics of another member.
    I have modified a test account to match with the profile settings of that member, but the test account cannot see the private album.

    Comment

    • TheNewOne
      Senior Member
      • Aug 2011
      • 1033
      • 4.2.5

      #3
      Check Profile Privacy for each member as each member has the option to allow members to either see or not see parts of their profile this also includes albums

      Comment

      • flashgordon
        Senior Member
        • Sep 2006
        • 206
        • 3.5.x

        #4
        The problem above was related to the difference between buddies and friends. If you are on somebody's buddy list, you can view their private pics. On the other hand, you will not show up on their friends list, because buddies are not listed there. That was what irritated the member.

        ---

        But another problem has come up. Member "A" sent member "B" a friend request. It was left pending by member B. That means, member B is on member A's contact list (as a buddy), but member A is not on member B's list.
        However, member A left a comment on a private picture of member B. That should not be possible. Member A is not a buddy of member B. Member B left the friend request pending. The private albums of member B should be hidden for member A.

        How is it possible that the member commented on the private album picture?

        Comment

        widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
        Working...