TheRosettaFoundation / SOLAS-Match

Self-managed translation project interface
www.TheRosettaFoundation.org
GNU Lesser General Public License v3.0
12 stars 8 forks source link

Peoples seem are able to get to Restricted Tasks (by guessing URLs?), so redirect to Home #1273

Closed alanbarrett closed 7 years ago

alanbarrett commented 7 years ago

@Paulina-Rosetta @stefania91 requested... This has happened before but it’s getting to a point where we have to think about intervening. A restricted task (Qualified badge) has been claimed by a user who does not hold the badge. We think it’s because they came across the task when it was displayed on a different task page in the ‘Users also viewed’ section on the right. But we can’t be sure.

The previous one was claimed on 4 April: https://trommons.org/task/21064/view/ The user who claimed it https://trommons.org/17448/profile/ definitely does not have a badge.

Alan... I will look at this again. I am pretty sure it is not ‘Users also viewed’ as the SQL for that checks Restricted Tasks. I will check again, and if I cannot see where they are getting to view the task, I will stop them claiming it.

Alan... Peoples seem are able to get to Restricted Tasks (by guessing URLs?), so redirect to Home if they do this.

Alan.
alanbarrett commented 7 years ago

This is now done... Restricted tasks should not be accessible (unless you have a Qualified Badge). You will get : "You are not authorized to view this page".

Alan.