• Resolved yikyak

    (@yikyak)


    Hi Kevin et al,
    I am running several sites on a WordPress multisite, was running the latest WP 5.9 and latest PublishPress Permission 3.7, one of my users reported that they could see a lot of content they felt they shouldn’t be able to see (and indeed has not previously seen).
    It looks like my access control on various sites has pretty much disintegrated, users can see posts in categories that they should be completely blocked from, and can see pages they should be completely blocked from. And I suspect they were completely blocked from this content until “recently” (I notice a few PPP updates in recent times, and I can’t be any more specific about when the problems began).
    Initially, I was checking settings on categories, sub-categories, and even then on a few individual posts in an attempt to hide stuff, it was kinda working, but then I appreciated the scale of the reveal. Some of the settings seemed puzzling to me (lots of “default yes” that I wouldn’t expect, but I hadn’t looked at some of my category settings for a long time). I don’t know if somehow the settings had changed, or if some recent plugin update has just caused a wider failure of the access control concept?
    I’ve reverted the plugin to 3.6.5 (simply on the grounds another user reported some different issues after this version) and this seems to have reset things to good access control. I’ve no idea what’s going on.
    Help?
    Kind regards
    YikYak

Viewing 7 replies - 1 through 7 (of 7 total)
  • Plugin Author Steve Burge

    (@stevejburge)

    Hi @yikyak

    Thanks for using PublishPress Permissions.

    Sorry, there’s not much here that developers like us can work with. I’d recommend setting up a test site and see if you can share any detailed feedback.

    For our Pro members, we can take general “things are broken” questions and help debug them.

    As a Free users on ww.wp.xz.cn, please do some debugging and see if you can report specific issues for us to fix.

    Thread Starter yikyak

    (@yikyak)

    Understood, it was a panic posting as I was also just trying to get my site back under control.
    I don’t think I can set up a test site easily, but I can experiment with different versions of the PPP plugin to see when I notice a break/failure of some sort.
    Other than that, what sort of things might you look for me to report? Can you give me any clues about what you might want to read?
    Kind regards
    YikYak

    Plugin Author Steve Burge

    (@stevejburge)

    Thanks @yikyak

    Ideally, we’re looking for a report we can replicate.

    If you say feature X is broken, our aim is to follow your report, test, and see the same issue.

    Plugin Author Kevin Behrens

    (@kevinb)

    @yikyak I’ve confirmed that version 3.7 disabled Category / Taxonomy permissions. Other methods of permission control are not affected.

    I’ve reverted the stable version to 3.6.9 and will follow with a fix as soon as possible.

    Plugin Author Kevin Behrens

    (@kevinb)

    @yikyak Permissions 3.7.1 fixes the Category / Taxonomy exclusion failure.

    Plugin Author Kevin Behrens

    (@kevinb)

    @yikyak If you can confirm this fix to help prevent general panic, that would be good.

    Thread Starter yikyak

    (@yikyak)

    Hi Kevin,
    Sorry for the delay, wrong time of day over here. Yes, just done a little bit of testing, 3.7.1 seems to be OK, things are back with controlled access as I would expect.
    Kind regards
    YikYak

Viewing 7 replies - 1 through 7 (of 7 total)

The topic ‘Access Control has Disintegrated’ is closed to new replies.