ISSUE SUMMARY:
Activites within Private group is displayed at the activity stream of any user, including users that are not members at that private group.
Pressing on the group name at the activity records takes the unauthorized user to see everything at that group.
Privacy violation !!!!
please advise.
regards,
Udi
STEPS TO REPLICATE:
1
2
3
4
5
RESULT
EXPECTED RESULT
BROWSER
Hi, Udi.
I'm sorry but here is no privacy violation. Take a look here:
- I created a private test group and upload photo to it. This is what I see on stream when viewing as group member:
prntscr.com/7kc418
- and this is what I see when I'm logged in as group non-member:
prntscr.com/7kc4l9
So I can't see post from private group. They are displayed ONLY for group member or Super User.
Please, make own test. Log in as group member, post something. Then log out and check with group non-member. No post should be visible.
Hi Michal,
Thank you for your great support.
The example you sent is ok so I did the same:
- Created a new private group from the frontpage. png#1
- defined is as private.
Now login:
- as the group creator - see activity stream png#2
- as a non-member of the group png#3
No difference in activity stream.
Your sheep is displayed correctly at those png's
What do I do wrong?
Please advise.
regards,
Udi
Hi, Udi.
Your printscreens are correct. Super User is a private group member so he can see sheep photo (test.ghc.org3216-3.png).
But when you log in as other user - you may created new private group but will not see sheep photo (test.ghc.org3216-4.png)
When I log in as my user (private group non-member) I can see only this:
prntscr.com/7kdfx5
But when I logged in as Super User I was able to see the same as you, then join group and upload photo:
prntscr.com/7kddqz
Conclusion: stream privacy works perfectly on your site :) You can see activities from private group because you're Super User and have privileges to do so ;)
Hi, Udi.
Please, upload printscreens here as they are too small on forum:
prnt.sc/
You mean that user is in certain Joomla! user group?
My user is in Registered Joomla! group.