Please upgrade here. These earlier versions are no longer being updated and have security issues.
HackerOne users: Testing against this community violates our program's Terms of Service and will result in your bounty being denied.

Approval Method Not Working: Pending Users Can Still Post Discussions

edited September 2016 in Vanilla 2.0 - 2.8

We are experiencing an issue with with the "Approval" method. When a new user account is created that user can immediately post new discussions despite us using the "Approval" method and disabling the email confirmation setting.

Steps to reproduce:

  1. Go to Recovery.org/forums
  2. Click on "Join" and create an account. Your account theoretically should be pending.
  3. Go to the "Forums" link at the top of the page and create a new discussion (please use a "." in the subject and body line because this is a live forum and we don't want "test" emails showing up if possible.

You will be able to post a discussion despite your account being listed in the Applicant pending list.

The account is successfully wiped out once the admin/moderator selects "Decline" but the user can still post freely in the meantime. This completely negates the purpose of having an approval process. Please help!

The client is still using 2.1.1 and feels it's too risky to update. Is this a flaw in the system? Is there any way to resolve this without updating?

Thanks in advance!

Comments

Sign In or Register to comment.