Kunena 6.2.4 Released

The Kunena team has announce the arrival of Kunena 6.2.4 [K 6.2.4] which is now available for download as a native Joomla extension for J! 4.3.x/4.4.x/5.0.x. This version addresses most of the issues that were discovered in K 6.1 / K 6.2 and issues discovered during the last development stages of K 6.2

Solved Editing/Disabling Open Graph Meta Tags [SOLVED]

More
5 years 4 weeks ago - 5 years 3 weeks ago #1 by OpenTexts
Hello, I have found a security hole with Open Graph tags.

When I set to show only display names (not logins), they work normally with Kunena. But if I open a page source, I can find there a real login as a meta tag (<meta property="og:author").

How can I completely disable generating this?

Thank you.
Last edit: 5 years 3 weeks ago by OpenTexts. Reason: Removing a forum report information. Setting a [SOLVED] status.

Please Log in or Create an account to join the conversation.

More
5 years 4 weeks ago #2 by ssh
Let's wait for a fix.

in the meanwhile, you can comment the line 453 in /components/com_kunena/controller/topic/item/display.php;

Code:
//$this->setMetaData('og:author', $this->topic->getAuthor()->username, 'property');
The following user(s) said Thank You: OpenTexts

Please Log in or Create an account to join the conversation.

More
5 years 4 weeks ago #3 by OpenTexts

ssh wrote: Let's wait for a fix.

in the meanwhile, you can comment the line 453 in /components/com_kunena/controller/topic/item/display.php;

Code:
//$this->setMetaData('og:author', $this->topic->getAuthor()->username, 'property');


Thank you! Partially it works. But I have found one more place in that code, which also displays a name:
Code:
"@type": "Person", "name": "LOGIN_NAME"

Please Log in or Create an account to join the conversation.

More
5 years 3 weeks ago #4 by ruud
Hi, og:author is a non-existing tag and should NOT be used.
see below the information from facebook when using the og:author tag:

sharing = caring
Attachments:

Please Log in or Create an account to join the conversation.

More
5 years 3 weeks ago - 5 years 3 weeks ago #5 by OpenTexts

ruud wrote: Hi, og:author is a non-existing tag and should NOT be used.
see below the information from facebook when using the og:author tag:

I have already disabled this tag as ssh wrote. But this "author" thing is more complicated than I thought before. At this Kunena official forum I don't see this mistake as I see on my site. IDK why.
Last edit: 5 years 3 weeks ago by OpenTexts.

Please Log in or Create an account to join the conversation.

More
5 years 3 weeks ago #6 by OpenTexts
I have found a temporary solution for this issue. As ssh wrote above about a file location, where we can disable Open Graph (site_root/components/com_kunena/controller/topic/item/display.php), we can comment another line to completely block any user login leaking there:
Code:
//$tmp->{'name'} = $this->topic->getLastPostAuthor()->username;

Please Log in or Create an account to join the conversation.

Time to create page: 0.321 seconds