Access to other's listing by changind pid in browser

This topic contains 1 reply, has 2 voices, and was last updated by  Stiofan O’Connor 4 years, 11 months ago.

We have moved to a support ticketing system and our forums are now closed.

Open Support Ticket
  • Author
    Posts
  • #490801

    Nicolas Wuergler
    Expired Member
    Post count: 7

    When a regular user is on the listing page he can not only change his own listing but through changing the pid in the browser address bar he can also access and change someone else’s listing. How can I prevent this? Thank you.

    #490842

    Stiofan O’Connor
    Site Admin
    Post count: 22956

    Hello,

    This was based on user role abilities in the past and we have updated this so that only admins and the listing author will even be shown the edit screen. A new function to check this and show a appropriate message to the user has been added and will be in the release tomorrow.

    If you need it sooner you can download the latest from our github repo here: https://github.com/AyeCode/geodirectory

    Thanks,

    Stiofan

Viewing 2 posts - 1 through 2 (of 2 total)

We have moved to a support ticketing system and our forums are now closed.

Open Support Ticket