Bug: Unauthorized user, when requesting login details is able to download attachments

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • tpearl5
    Senior Member
    • Jul 2001
    • 547
    • 4.2.X

    Bug: Unauthorized user, when requesting login details is able to download attachments

    I couldn't find this in the current bugs, but here's what I found.

    When a user goes to donwload an attachment, but doesn't have permission, or isn't logged in, they get the unauthorized login page. From there, if they request their password (type in e-mail and submit), the confirmation screen comes up and the download box comes up for the file.

    I don't know if this is just my board or what. If someone else can duplicate it, then it's a bug. I have unregistered users and non confirmed users set do they can't download attachments in one forum.

    Capture more registrations - Advanced Guest Posting & Registration
    Cell Phone Forums | Nikonites
  • Kickstand
    New Member
    • Oct 2001
    • 2

    #2
    There is another problem with attachments also. I have "guests" set so that they can not download attachments.
    But if they have the url to the attachment, they can go right to it. Completely bypassing any kind of "permission" settings. This is with 2.2.2 and is very repeatable.

    Comment

    • tubedogg
      Senior Member
      • Feb 2001
      • 13602

      #3
      Kickstand what you are saying is just not possible, if your permissions are indeed setup correctly, as there is permission checking in attachment.php itself.

      Comment

      • Kickstand
        New Member
        • Oct 2001
        • 2

        #4
        Sorry tubedogg,
        You are correct, my permissions were not set the way I thought that they were. Somehow, probably something I did with out realizing it, my "guest can download attachments" got set to enabled. My mistake.

        Comment

        Related Topics

        Collapse

        Working...