[wp-trac] [WordPress Trac] #11810: Some users able to comment on unpublished posts

WordPress Trac wp-trac at lists.automattic.com
Thu Jan 7 17:50:03 UTC 2010


#11810: Some users able to comment on unpublished posts
--------------------------+-------------------------------------------------
 Reporter:  ericmann      |       Owner:       
     Type:  defect (bug)  |      Status:  new  
 Priority:  normal        |   Milestone:  2.9.2
Component:  Comments      |     Version:  2.9.1
 Severity:  normal        |    Keywords:       
--------------------------+-------------------------------------------------

Comment(by filosofo):

 Patch attached, but not using current_user_can() check, because it returns
 false for non-logged-in users.

 Since we don't allow comments on "pending" despite capability, there's no
 reason to allow them on "future," right?

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/11810#comment:8>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list