Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Changing album group permissions doesn't work properly #2143

Open
MikeImbar opened this issue Apr 3, 2024 · 1 comment
Open

Changing album group permissions doesn't work properly #2143

MikeImbar opened this issue Apr 3, 2024 · 1 comment

Comments

@MikeImbar
Copy link

MikeImbar commented Apr 3, 2024

If I change album permissions for a user group, e.g. make a sub-album private, I can do that via the admin panel -> Users -> Groups -> Manage permissions. The issue is that the album doesn't actually become private. It is still visible to users from that group. However, it will be private to newly registered users that by default belong to that group. So you end up with users belonging to the same user group seeing different things, maybe even albums that you want to be private. This is a bit of a serious security issue.

The workaround is moving the whole album to the 'Forbidden' section and then moving the ones that you want to make public back to the 'Authorized' section. This is not clear at all that this is how it works and now I wonder how many albums in my gallery are public to certain user groups when they should be private....

@flop25
Copy link
Member

flop25 commented Apr 3, 2024

Hello
That's concerning.
could you provide a step by step procedure to reproduce with urls of the pages. That's the best way to be sure there is no misunderstanding. Thank you

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants