Issue Tracker pages can be viewed via direct link

9 years 9 months ago #1 by madrus
We have installed this extension and trying to learn how to work with it. There is one issue we have run into lately. Maybe you know the solution for it. We can’t protect the issue pages from being viewed from outside. I mean, everything works fine when opening issues via the Issue Tracker. Then each regular customer can only see his own issues and not those of other customers. Yet, the same page can be sometimes found through the Google search and opened by anyone via such a direct link! Here is an example:

A protected issue visible to public

How can we protect our issues from being viewed by unauthorized (public) visitors?

Please Log in or Create an account to join the conversation.

9 years 9 months ago #2 by geoffc
The usual Joomla ACL rules usually apply. Look at the 'access' on the one of the issues visible to the public. If it is set to 'Public' change it to 'Registered'.

Now retry the test. The issue should not be visible to guest (public) users.

As to the search visibiliy is this with the Joomla search or the Joomla Smart Search 'Finder' search? I believe the same rules apply to both but its a while since I last looked at this.

The long answer is that to be visible the issue has to be published and not marked 'private' and the viewer has to be in on of the authorised access groups.

Regards
Geoff

Please Log in or Create an account to join the conversation.

Time to create page: 0.142 seconds
Go To Top

Joomla! Debug Console

Session

Profile Information

Memory Usage

Database Queries