[wp-trac] [WordPress Trac] #11695: Comments on private posts can be view by anyone via RSS

WordPress Trac wp-trac at lists.automattic.com
Sun Aug 5 14:27:17 UTC 2012


#11695: Comments on private posts can be view by anyone via RSS
-------------------------------------+-------------------------
 Reporter:  palotasb                 |       Owner:
     Type:  defect (bug)             |      Status:  closed
 Priority:  high                     |   Milestone:
Component:  Comments                 |     Version:
 Severity:  normal                   |  Resolution:  worksforme
 Keywords:  has-patch needs-testing  |
-------------------------------------+-------------------------
Changes (by SergeyBiryukov):

 * keywords:  featured has-patch needs-testing => has-patch needs-testing
 * status:  new => closed
 * resolution:   => worksforme
 * milestone:  Future Release =>


Comment:

 I could not reproduce this using the steps provided in the description
 neither in 2.8 or 2.9 (when the ticket was created), nor in current trunk.

 When a logged out user tries to view a private post's comment feed,
 `$wp_query->posts` is set to an empty array due to the check in
 `get_posts()`: [[BR]]
 http://core.trac.wordpress.org/browser/tags/3.4.1/wp-
 includes/query.php#L2674

 `handle_404()` then issues a 404 error: [[BR]]
 http://core.trac.wordpress.org/browser/tags/3.4.1/wp-includes/class-
 wp.php#L463

 Feel free to reopen with more information if there's still a problem.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/11695#comment:13>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list