[wp-trac] [WordPress Trac] #4353: Users with edit_posts capability can see everyone's comments, IPs, and email addresses

WordPress Trac wp-trac at lists.automattic.com
Wed Sep 9 22:10:48 UTC 2009


#4353: Users with edit_posts capability can see everyone's comments, IPs, and
email addresses
----------------------------------------------------------+-----------------
 Reporter:  idahofallzcom                                 |        Owner:  markjaquith
     Type:  enhancement                                   |       Status:  reopened   
 Priority:  high                                          |    Milestone:  2.9        
Component:  Comments                                      |      Version:  2.7        
 Severity:  normal                                        |   Resolution:             
 Keywords:  needs-patch reporter-feedback needs-testcase  |  
----------------------------------------------------------+-----------------

Comment(by dd32):

 > Is there a testcase to actually figure out that this is something else
 then worksforme? if not this should be closed.

 As the ticket says, Use a user with the 'edit_posts' capability. So that
 means a user role which can edit posts or use a Role management plugin to
 modify a role for it.

 I'm pretty sure this would've been fixed by (In [7322])  in the sense that
 If you cant edit the comment, You cant view those details, so.. not
 entirely sure.

 Try with a contributor role. (And close it in 2.7 milestone as fixed if
 theres no problem)

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/4353#comment:15>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list