Moderators still able to access other users bookmarks

Summary:

When the changes were made to the user profile page, moderators were supposed to lose access to other users bookmarks. While the tab was removed from the left menu, if a moderator navigates to another user’s profile directly by URL, they are still given access to the bookmarks.

Steps to reproduce:

  1. Navigate to $site_url/users/user_name_here/activity/bookmarks as moderator

Expected Results:

Receive access denied error message

Actual Results:

View user’s bookmarks

Notes:

Continuing the discussion from Moderators cannot view bookmarks on other user’s activity pages

Attachments:

None for privacy reasons.

Version:

Discourse 1.5.0.beta9 (discourse.stonehearth.net)

System Information:

Windows 10 Pro, Chrome Stable 48

4 Likes

This seems to be resolved as of 1.6.0.beta1. Attempting to modify the URL to point to another user no longer displays their bookmarks, it instead displays a (mostly) blank profile page.

4 Likes