# Topic title restrictions are bypassed when category is changed in combination with title edit

**URL:** <https://meta.discourse.org/t/topic-title-restrictions-are-bypassed-when-category-is-changed-in-combination-with-title-edit/267100>\
**Category:** Bug\
**Created:** [June 3, 2023, 5:32pm UTC](https://meta.discourse.org/t/topic-title-restrictions-are-bypassed-when-category-is-changed-in-combination-with-title-edit/267100 "2023-06-03T17:32:21Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![per1234](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/per1234/32/569645_2.png) [@per1234](https://meta.discourse.org/u/per1234)\
**Post date:** [June 3, 2023, 5:32pm UTC](https://meta.discourse.org/t/topic-title-restrictions-are-bypassed-when-category-is-changed-in-combination-with-title-edit/267100/1 "2023-06-03T17:32:21Z")

</div>

### Priority/Severity:

Medium

### Platform

Windows 11

Google Chrome 114.0.5735.90 (Official Build) (64-bit)

### Description:

Several restrictions on topic titles can be configured via the administrative settings. These include:

- `min topic title length`
- `title min entropy`
- `max emojis in title`
- `allow duplicate topic titles`

If the user changes the category when editing the topic title, the checks for compliance with these restrictions are bypassed.

### Reproducible steps:

1. Click the “ **New Topic** ” button.
2. Add some text to the post field.
3. Click the “ **Create Topic** ” button.  
🙂 A “ **Title is required** ” error appears.
4. Add a compliant title in the “ **Type title, or paste a link here** ” field.
5. Click the “ **Create Topic** ” button.  
🙂 The topic is created.
6. Click the pencil icon to the right of the topic title.  
The topic edit UI opens.
7. Change the title to `aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa`
8. Click the **✓** button in the topic edit UI.  
🙂 A dialog appears:

> **An error occurred: Title seems unclear, most of the words contain the same letters over and over?**

9. Click the the “ **OK** ” button in the dialog.
10. Select another category from the category dropdown menu.
11. Click the **✓** button in the topic edit UI.  
🙂 A dialog appears:

> **An error occurred: Title seems unclear, most of the words contain the same letters over and over?**

12. Click the the “ **OK** ” button in the dialog.
13. Click the the **X** button in the dialog.
14. Reload the page.  
🐛 Despite the indications to the contrary, the edit was successful. The topic now has a title in violation of the `title min entropy` setting.
15. Click the pencil icon to the right of the topic title.  
The topic edit UI opens.
16. Change the title to `🙃🙃🙃🙃🙃🙃🙃🙃 This title has many emoji`
17. Click the **✓** button in the topic edit UI.  
🙂 A dialog appears:

> **An error occurred: Title can’t have more than 1 emoji**

18. Click the the “ **OK** ” button in the dialog.
19. Select another category from the category dropdown menu.
20. Click the **✓** button in the topic edit UI.  
🐛 The edit is successful. The topic now has a title with multiple emoji, in violation of the `max emojis in title` setting.
21. Click the pencil icon to the right of the topic title.  
The topic edit UI opens.
22. Change the title to a title that is already used by another topic on the forum.
23. Click the **✓** button in the topic edit UI.  
🙂 A dialog appears:

> **An error occurred: Title has already been used**

24. Click the the “ **OK** ” button in the dialog.
25. Select another category from the category dropdown menu.
26. Click the **✓** button in the topic edit UI.  
🐛 The edit is successful. The topic now has a duplicate title, in violation of the `allow duplicate topic titles` setting.
27. Click the pencil icon to the right of the topic title.  
The topic edit UI opens.
28. Delete the text from the topic title field.
29. Click the **✓** button in the topic edit UI.  
🙂 A dialog appears:

> **Multiple errors occurred: 1) Title can’t be blank 2) Title is too short (minimum is 15 characters) 3) Title seems unclear, most of the words contain the same letters over and over?**

30. Click the the “ **OK** ” button in the dialog.
31. Select another category from the category dropdown menu.
32. Click the **✓** button in the topic edit UI.  
🐛 The edit is successful. The topic now has no title, in violation of the `min topic title length` setting:  
 ![image](https://global.discourse-cdn.com/meta/original/4X/3/c/b/3cb1caf87509df4bc71bf914f8cc41c4ee3cc0d3.png)
33. Reload the page.  
🐛 The page fails to load:

> ## This page isn’t working
> 
> **[try.discourse.org](http://try.discourse.org)** redirected you too many times.  
> Try clearing your cookies.  
> `ERR_TOO_MANY_REDIRECTS`

#### Additional context

I am able to reproduce the fault on [try.discourse.org](http://try.discourse.org) in “[safe mode](https://meta.discourse.org/t/how-to-use-discourse-safe-mode/53504)”.

---

<div class="post-metadata">

**Author:** ![twofoursixeight](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/twofoursixeight/32/574822_2.png) [@twofoursixeight](https://meta.discourse.org/u/twofoursixeight)\
**Post date:** [June 3, 2023, 7:09pm UTC](https://meta.discourse.org/t/topic-title-restrictions-are-bypassed-when-category-is-changed-in-combination-with-title-edit/267100/2 "2023-06-03T19:09:37Z")

</div>

I reproduced the “aaaaaaaaaaaaaaaaaaaaaaaa” section of the bug:

---

<div class="post-metadata">

**Author:** ![Lhc\_fl](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/lhc_fl/32/268115_2.png) [@Lhc\_fl](https://meta.discourse.org/u/Lhc_fl)\
**Post date:** [June 4, 2023, 3:37am UTC](https://meta.discourse.org/t/topic-title-restrictions-are-bypassed-when-category-is-changed-in-combination-with-title-edit/267100/3 "2023-06-04T03:37:07Z")

</div>

> [@per1234](#):
>
> Reload the page.  
> 🐛 The page fails to load:

I reproduced it and it looks like it’s due to unqualified topic\_slug

---

<div class="post-metadata">

**Author:** ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)\
**Post date:** [June 5, 2023, 1:20am UTC](https://meta.discourse.org/t/topic-title-restrictions-are-bypassed-when-category-is-changed-in-combination-with-title-edit/267100/4 "2023-06-05T01:20:15Z")

</div>

Feels borderline security to me… user is doing something they are not allowed to do.

Going to unlist this and prioritize internally, we should get it sorted in the next couple of weeks.

---

<div class="post-metadata">

**Author:** ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)\
**Post date:** [June 5, 2023, 1:20am UTC](https://meta.discourse.org/t/topic-title-restrictions-are-bypassed-when-category-is-changed-in-combination-with-title-edit/267100/5 "2023-06-05T01:20:19Z")

</div>



---

<div class="post-metadata">

**Author:** ![per1234](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/per1234/32/569645_2.png) [@per1234](https://meta.discourse.org/u/per1234)\
**Post date:** [June 5, 2023, 2:55am UTC](https://meta.discourse.org/t/topic-title-restrictions-are-bypassed-when-category-is-changed-in-combination-with-title-edit/267100/7 "2023-06-05T02:55:18Z")

</div>

I apologize if I didn’t use the appropriate reporting workflow **sam**.

---

<div class="post-metadata">

**Author:** ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)\
**Post date:** [June 5, 2023, 2:56am UTC](https://meta.discourse.org/t/topic-title-restrictions-are-bypassed-when-category-is-changed-in-combination-with-title-edit/267100/8 "2023-06-05T02:56:32Z")

</div>

No worries at all, this particular one is borderline. We have still not 100% determined if this is CVE worthy or not, I am just being extra cautious.

---

<div class="post-metadata">

**Author:** ![davidb](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/davidb/32/554671_2.png) [@davidb](https://meta.discourse.org/u/davidb)\
**Post date:** [June 14, 2023, 8:05am UTC](https://meta.discourse.org/t/topic-title-restrictions-are-bypassed-when-category-is-changed-in-combination-with-title-edit/267100/10 "2023-06-14T08:05:56Z")

</div>

I have been able to reproduce all the steps outlined in this topic. It seems like the topic validator is working to add the correct errors, but somehow the update transaction is not ensuring it’s valid before saving.

The biggest concern from these issues is the blank/empty topic title (last step), mainly because the page will keep reloading (infinite loop that is triggered from [here](https://github.com/discourse/discourse/blob/main/app/controllers/topics_controller.rb#L165-L168)). Aside from that it’s mainly a usability issue, as topics cannot be clicked from `/latest` as the title link does not exist.

---

<div class="post-metadata">

**Author:** ![nat](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nat/32/235063_2.png) [@nat](https://meta.discourse.org/u/nat)\
**Post date:** [July 24, 2023, 2:56am UTC](https://meta.discourse.org/t/topic-title-restrictions-are-bypassed-when-category-is-changed-in-combination-with-title-edit/267100/14 "2023-07-24T02:56:52Z")

</div>

@per1234 Thank you for the report. You should have received the fix to this issue.

> **[Topic Title Validation Skipped When Changing Category](https://github.com/discourse/discourse/security/advisories/GHSA-4hjh-wg43-p932)**
>
> \### Impact
> When editing a topic, there is a vulnerability that enables a user to bypass the topic title validations for things like title length, number of emojis in title and blank topic titles.
> ...

---

<div class="post-metadata">

**Author:** ![nat](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nat/32/235063_2.png) [@nat](https://meta.discourse.org/u/nat)\
**Post date:** [July 26, 2023, 2:57am UTC](https://meta.discourse.org/t/topic-title-restrictions-are-bypassed-when-category-is-changed-in-combination-with-title-edit/267100/15 "2023-07-26T02:57:56Z")

</div>

This topic was automatically closed after 2 days. New replies are no longer allowed.
