Jump to content

Opening specific status update link allows me to post as 'Guest'

minibois
Go to solution Solved by colonel_mortis,

Thanks, this should now be fixed.

Browser, version and OS: applicable to at least Chrome/Edge/Firefox, current versions on Windows 10.

Spoiler

Chrome: Version 85.0.4183.102

Edge: Version 85.0.564.51

FireFox: 80.0.1

Steps to reproduce/what were you doing before it happened?

Opening a specific status update link* (with some notification parameters) in a browser where you're not logged in (such as an incognito window) allows me to reply to said status update as a "Guest".

Clicking on a timestamp under any of the replies shows me a "Complete your profile" page, which tells me to insert my e-mail and display name, which I assume is what new users see when signing up.

 

*this status update link (with its parameters) probably came form those "popup" notifications in the bottom (left) of your screen (but was just normally copied from the browser's URL bar). 

 

What happened?

Opening a status update in an incognito window showed me signed up as 'Guest' and allowed me to comment as such user.

 

What did you expect to happen?

Normally you wouldn't see a reply box and a "Sign up" button

 

Link to a page where it happened, if applicable: 

I don't think sharing the link would be a great idea in this case, so I think sharing it via PM is a better.

It's a normal status update link, but with a 'fromNotification' & 'notificationToken' parameters.

 

Screenshots of the issue, if applicable: 

image.png.0ebeec19f99bf52c09719a6cdbc46453.png

 

Clicking on any link:

image.png.1e5a171fc8fdbc8a396c83970fcafbf5.png

 

Normally:

image.png.a75a5bdf86e9620a45e7000f7fd15e56.png

(no "Reply to this status" option, "Sign Up" button and clicking on a link works as it should).

 

If it's a cloudflare error, what was the ray ID from the bottom of the error page? 

N/A

"We're all in this together, might as well be friends" Tom, Toonami.

 

mini eLiXiVy: my open source 65% mechanical PCB, a build log, PCB anatomy and discussing open source licenses: https://linustechtips.com/topic/1366493-elixivy-a-65-mechanical-keyboard-build-log-pcb-anatomy-and-how-i-open-sourced-this-project/

 

mini_cardboard: a 4% keyboard build log and how keyboards workhttps://linustechtips.com/topic/1328547-mini_cardboard-a-4-keyboard-build-log-and-how-keyboards-work/

Link to comment
Share on other sites

Link to post
Share on other sites

This is the link I posted : https://linustechtips.com/main/profile/757582-d75ef185e18105c25f4e200007446bbd/

 

 

~~this was not the link I posted, it was off my notifications on my phone, but either way it led to this.~~

~New~  BoomBerryPi project !  ~New~


new build log : http://linustechtips.com/main/topic/533392-build-log-the-scrap-simulator-x/?p=7078757 (5 screen flight sim for 620$ CAD)LTT Web Challenge is back ! go here  :  http://linustechtips.com/main/topic/448184-ltt-web-challenge-3-v21/#entry601004

Link to comment
Share on other sites

Link to post
Share on other sites

This is beginning to look like some missingno level stuff

image.png.44655b85c7bfb3d27e06eae204ef9347.png

Intel® Core™ i7-12700 | GIGABYTE B660 AORUS MASTER DDR4 | Gigabyte Radeon™ RX 6650 XT Gaming OC | 32GB Corsair Vengeance® RGB Pro SL DDR4 | Samsung 990 Pro 1TB | WD Green 1.5TB | Windows 11 Pro | NZXT H510 Flow White
Sony MDR-V250 | GNT-500 | Logitech G610 Orion Brown | Logitech G402 | Samsung C27JG5 | ASUS ProArt PA238QR
iPhone 12 Mini (iOS 17.2.1) | iPhone XR (iOS 17.2.1) | iPad Mini (iOS 9.3.5) | KZ AZ09 Pro x KZ ZSN Pro X | Sennheiser HD450bt
Intel® Core™ i7-1265U | Kioxia KBG50ZNV512G | 16GB DDR4 | Windows 11 Enterprise | HP EliteBook 650 G9
Intel® Core™ i5-8520U | WD Blue M.2 250GB | 1TB Seagate FireCuda | 16GB DDR4 | Windows 11 Home | ASUS Vivobook 15 
Intel® Core™ i7-3520M | GT 630M | 16 GB Corsair Vengeance® DDR3 |
Samsung 850 EVO 250GB | macOS Catalina | Lenovo IdeaPad P580

Link to comment
Share on other sites

Link to post
Share on other sites

I think I know what this link will look like, but can you pm it to me as a sanity check while I investigate? 

HTTP/2 203

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, colonel_mortis said:

Thanks, this should now be fixed.

It is indeed fixed (on my end).

 

Thanks for getting to this so quickly!

you da best!

"We're all in this together, might as well be friends" Tom, Toonami.

 

mini eLiXiVy: my open source 65% mechanical PCB, a build log, PCB anatomy and discussing open source licenses: https://linustechtips.com/topic/1366493-elixivy-a-65-mechanical-keyboard-build-log-pcb-anatomy-and-how-i-open-sourced-this-project/

 

mini_cardboard: a 4% keyboard build log and how keyboards workhttps://linustechtips.com/topic/1328547-mini_cardboard-a-4-keyboard-build-log-and-how-keyboards-work/

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×