Kunena 7.0.5 & Kunena 6.4.11 – Security Updates Released

The Kunena team has announce the arrival of Kunena 7.0.5 [K 7.0.5] in stable which is now available for download as a native Joomla extension for J! 5.4.x/6.0.x. This version addresses most of the issues that were discovered in K 6.2 / K 6.3 / K 6.4 and issues discovered during the last development stages of K 7.0.

The Kunena team is also pleased to announce the eleventh version of Kunena 6.4, a native Joomla extension for Joomla! 5.0, 5.1, 5.2, 5.3, 5.4 and 6.0.

Topics that are moved into this category are generally considered to be closed. Users may want to add additional information but these topics should not be resurrected in order to discuss new problems or unrelated matters.

Solved RSS circumvents access rights for topics/sections

More
11 years 11 months ago #156460 by Leviathan
Hello!

First I would like to introduce an example set up:
Let us say, there are two sections and two users, one administrator and one regular user. One section is accessible for administrators only. The regular user cannot access the administrator section directly, but if the RSS is configured to show the recent messages, the regular user can still read the messages from the section he has no rights for!

Can you see my problem? Do you consider this a bug? Is there a workaround?

cheers, Leviathan

Please Log in or Create an account to join the conversation.

More
11 years 11 months ago #156483 by sozzled

Leviathan wrote: Can you see my problem?

No, we cannot see your problem.

Leviathan wrote: Do you consider this a bug?

I do not know how to answer this question because I do not know what you want us to do for you. This is how the RSS feed is configured here, at www.kunena.org , and the RSS feed works properly.



With this configuration no-one is able to view the messages posted to "restricted" categories. An example of a "restricted" category on this website is the Custom work - not offering to pay category. A "restricted" category is a category that you cannot see until you login.

Because the RSS feed does not "login" this means that people cannot see messages posted in restricted categories.

For further background on this topic, see RSS - also "only for the Members area"

Please Log in or Create an account to join the conversation.

More
11 years 11 months ago - 11 years 11 months ago #156491 by Leviathan
Hm, actually I can read the titles of the topics discussed and the users who posted in these topics from your first link and RSS - also "only for the Members area" via RSS although I am not logged in. :unsure:

See for yourself what the RSS-Button yields:


Last edit: 11 years 11 months ago by Leviathan.

Please Log in or Create an account to join the conversation.

More
11 years 11 months ago - 11 years 11 months ago #156497 by sozzled

Leviathan wrote: Hm, actually I can read the titles of the topics discussed and the users who posted in these topics from your first link and RSS - also "only for the Members area" via RSS although I am not logged in. :unsure:

There are no restictions on reading that topic. The Feature Requests Archive category is not a restricted category.

Try reading the topics in the Custom work - not offering to pay category via RSS.
Last edit: 11 years 11 months ago by sozzled.

Please Log in or Create an account to join the conversation.

More
11 years 11 months ago - 11 years 11 months ago #156508 by Leviathan
Like I said, this works too! Here are the first few lines from the RSS of Custom work - not offering to pay as a not logged in user:
Code:
<?xml version="1.0" encoding="utf-8"?> <!-- generator="Kunena Forum (Joomla)" --> <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"> <channel> <title>Kunena - To Speak! Next Generation Forum Component for Joomla - Kunena - To Speak! Next Generation Forum Component for Joomla - Kunena - Recent Discussions</title> <description><![CDATA[Kunena! - To Speak! Next Generation Forum Component for Joomla]]></description> <link>http://www.kunena.org</link> <lastBuildDate>Thu, 29 May 2014 05:24:03 -0700</lastBuildDate> <generator>Kunena Forum (Joomla)</generator> <atom:link rel="self" type="application/rss+xml" href="http://www.kunena.org/forum/recent?format=feed&amp;type=rss"/> <image> <url>/components/com_kunena/template/blue_eagle/images/icons/rss.png</url> <title>Kunena - To Speak! Next Generation Forum Component for Joomla - Kunena - Recent Discussions</title> <link></link> <description><![CDATA[Kunena! - To Speak! Next Generation Forum Component for Joomla]]></description> </image> <language>en-gb</language> <item> <title>&quot;Performing maintenance (cleanup)...&quot; message</title> <link>http://www.kunena.org/forum/154-Miscellaneous-off-topic-and-general-Joomla/130770-performing-maintenance-cleanup-message?start=10#156507</link> <guid isPermaLink="true">http://www.kunena.org/forum/154-Miscellaneous-off-topic-and-general-Joomla/130770-performing-maintenance-cleanup-message?start=10#156507</guid> <description><![CDATA[Many thanks for your in depth reply.<br /> <br /> It is most appreciated to find you have gone to such lengths to try to resolve the problem.<br /> <br /> I have now managed to find the root of the problem - the message is generated by &quot;Mailster&quot;.<br /> They have owned up to it, and say the message is going to removed in the next release, as it is only an information thing.<br /> <br /> Like Kunena, Mailster is probably common to across many Joomla sites.<br /> <br /> Many thanks<br /> <br /> Peter]]></description> <category>Miscellaneous, off-topic and general Joomla</category> <pubDate>Thu, 29 May 2014 05:18:27 -0700</pubDate> </item> <item> <title>Packers Movers in Chennai | Moving Company in Chennai</title> <link>http://www.kunena.org/forum/k-3-0-general-questions/130806-packers-movers-in-chennai-moving-company-in-chennai#156506</link> <guid isPermaLink="true">http://www.kunena.org/forum/k-3-0-general-questions/130806-packers-movers-in-chennai-moving-company-in-chennai#156506</guid> <description><![CDATA[Chennai Packer Mover leading Packers and movers in Chennai- Start shifting your home with experienced and reliable moving company in Chennai, Corporate Moving Company.<br /> <br /> Regards,<br />

Did you try it yourself?
Last edit: 11 years 11 months ago by sozzled. Reason: Reformatted XML code

Please Log in or Create an account to join the conversation.

More
11 years 11 months ago - 11 years 11 months ago #156533 by sozzled
Yes, I tried this myself. What you have given us does not include anything from any restricted category. Unless you can show us an example of an RSS feed that includes information from a category that the RSS generator should not be able to access. I do not think that you have established proof of your claim.

Yes, you can click the RSS icon at the bottom of the page(s) in the Custom work - not offering to pay category but the output does not include information about messages posted in that category, does it?

I subscribe to the RSS feed at Kunena. I get notification every day (via the RSS feed) of new topics posted at this site. I do not get RSS feed notification of new topics posted in the restricted categories at this website here because the RSS feed does not have access to them.

Therefore I return to your first question: do I see your problem? No, I'm sorry, but I do not see your problem. What proof do you have that the RSS feed contains information about restricted information that only a site administrator should have access to?
Last edit: 11 years 11 months ago by sozzled.

Please Log in or Create an account to join the conversation.

Time to create page: 0.266 seconds