Online support system gives out info to unauthorized users
- Status
- Open
- Subject
- Online support system gives out info to unauthorized users
- Version
- 18.x
- Category
- Bug
- Easy for Newbie Dev
- Less than 30-minutes fix
- Feature
- Admin Interface (UI)
- Resolution status
- New
- Submitted by
- hman
- Lastmod by
- hman
- Rating
- Description
Tiki has an online support feature. In order to use it, users must become "operators" by granting from the admin. If they are no operator, and try to open the support console, then they get an error message, that they need to be operator. So far okay. I tried that feature (in order to translate it), and to do that I activated it. And as I wanted to see the error message that unauthorized users get, I clicked to open the support console.
Underneath the error message that I was no operator was the info "no support requests". That info IMHO should not be given out to non-operators.
- Importance
- 4
- Easy to solve?
- 10 easy
- Priority
- 40
- Demonstrate Bug on Tiki 19+
-
This bug has been demonstrated on show2.tiki.org
Please demonstrate your bug on show2.tiki.org
Show.tiki.org is not configured properlyThe public/private keys configured to connect to show2.tiki.org were not accepted. Please make sure you are using RSA keys. Thanks.
- Demonstrate Bug (older Tiki versions)
-
This bug has been demonstrated on show.tikiwiki.org
Please demonstrate your bug on show.tikiwiki.org
Show.tiki.org is not configured properlyThe public/private keys configured to connect to show.tikiwiki.org were not accepted. Please make sure you are using RSA keys. Thanks.
- Ticket ID
- 7456
- Created
- Sunday 02 August, 2020 14:03:51 UTC
by hman - LastModif
- Sunday 02 August, 2020 14:03:51 UTC