Please upgrade here. These earlier versions are no longer being updated and have security issues.
HackerOne users: Testing against this community violates our program's Terms of Service and will result in your bounty being denied.

How can I hide "Messages" when not signed in?

avantime4mikeavantime4mike ✭✭
edited February 2011 in Vanilla 2.0 - 2.8
Using the "Message" feature I placed a message at the top of all pages and included a hyperlink to a specific discussion. The problem is that this discussion is not normally accessible unless signed in, but non members can now click on my hyperlink and see a normally hidden discussion. I know I can hide the message from certain pages but I would like just to make the message visible on all pages only to signed in members.

Comments

  • Looks like security flaw inside Vanilla.
  • I did wonder about that. Could it be something to do with permissions on my server?
  • I doubt this.
    May be it just not check custom permissions in this case.
    I think that you must describe this step by step (including all permissions settings, link, etc).
    So others could check this also.
    I personally find that custom permissions work strange sometimes.
  • Just checked all my custom permissions for categories and they were all set to what I assume were defaults. Reset them all and everything is fine. I will keep an eye on this and report back if it happens again.
Sign In or Register to comment.