Logged out user can see TL locked categories in Safari

A user just reported this - safari mobile, any ideas?

we’re on commit hash 58cc35fc78

Do you have a link to your site you can share (in PM is fine) so I can check it out?

Sure thanks it’s https://tarck.cc

Myself and a few other users have tried to reproduce with no luck so not sure what else to try, sorry for the sparse report, not much in the errors logs apart from deprecation notices

1 Like

I can’t repro this on FF dev edition 106.0b9

Well, the good news is that I can’t see any of your private categories while browsing as an anon. I also can’t replicate this on Meta or my test site as anon, or having just logged out (using Safari on my iPhone).

Are there any other details about the specific circumstances you could give that I could try?

2 Likes

I think is possible if you are logged in and open the category page. Then you log out, disable your internet connection and open the category page again.

2 Likes

Thanks everyone for investigating. The user just mentioned that they did not even consciously log out, so I’m wondering if their auth cookie expired and they had a cached topic list or something? I’m confident that our locked categories aren’t publically visible but I appreciate a sanity check as it’s quite sensitive :relaxed:

2 Likes

So it’s just a cache mismatch because you are offline.

1 Like

Sounds right. What you’re seeing is the cached page from your machine, which you’ll get if the browser can’t access Discourse. Since they got the data before they were logged out, it’s not a bug. Or so I’d argue.

1 Like