"Last Post" stat exposes private message dates (privacy bug)

When you see “last post: x hours”, it considers private messages, too, which is pretty creepy and surely unintended.

1 Like

This is complete per:

https://github.com/discourse/discourse/commit/d8f7f363cd90c897aac1586ffc3da9c17af04187

We do not update last posted at for whispers and PMs any more

Caveats

  • If a user posts in a secure category this information is leaked to all users on the site

  • Moderators who used to rely on this date for moderation (Jane did nothing on the site since June) may be surprised to find that Jane indeed did post 12344 messages since June.

  • We do not “normalize” this date on post deletion, so if a user posts and then post is deleted we do not correct the value.

If you have issues with the caveats open a new #feature to discuss.

(note, I purged all old discussion here, it got heated and confusing)

8 Likes