<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Jivespace: Message List - can see projects in private communities without logging in</title>
    <link>http://www.jivesoftware.com/jivespace/community/support?view=discussions</link>
    <description>Most recent forum messages</description>
    <language>en</language>
    <pubDate>Mon, 17 Nov 2008 16:15:24 GMT</pubDate>
    <generator>Jive SBS 3.0.8 (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2008-11-17T16:15:24Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Re: can see projects in private communities without logging in</title>
      <link>http://www.jivesoftware.com/jivespace/message/142365?tstart=0#142365</link>
      <description>&lt;!-- [DocumentBodyStart:221b0af1-9a01-4da0-bed8-36e20c04f41c] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Hey Atul,&lt;/p&gt;&lt;p&gt;I'm going to close this ticket as it has already been addressed in your private support portal thread. Here was the findings for anyone that is having similar issues:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;div class="jive-quote"&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I verified that hidden projects are exposed in searchs, for example going to Browse &amp;gt; Projects &amp;gt; Search "project name" will return the project's name, community and end date.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;In my testing, I found user's can only see the projects listed in the search results, they cannot actually view the project or it's contents. Doing so will return an "unauthorized" error.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;This appears to be resolved in Clearspace 2.5.X but is still an issue in Clearspace 2.0.9, I've gone ahead and filed a bug for this: CS-9863. One of our developers will look into this further and resolve it in a future release of Clearspace 2.0.X... let me know if there's anything else I can add to this ticket or if you have any additional questions or concerns.&lt;/p&gt;&lt;br/&gt;&lt;br/&gt;&lt;/div&gt;&lt;br/&gt;&lt;br/&gt;&lt;span&gt; &lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;p&gt;~Long&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:221b0af1-9a01-4da0-bed8-36e20c04f41c] --&gt;</description>
      <pubDate>Mon, 17 Nov 2008 16:15:23 GMT</pubDate>
      <author>communities@jivesoftware.com</author>
      <guid>http://www.jivesoftware.com/jivespace/message/142365?tstart=0#142365</guid>
      <dc:date>2008-11-17T16:15:23Z</dc:date>
      <clearspace:dateToText>1 year, 4 days ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
    </item>
    <item>
      <title>can see projects in private communities without logging in</title>
      <link>http://www.jivesoftware.com/jivespace/message/139914?tstart=0#139914</link>
      <description>&lt;!-- [DocumentBodyStart:5b0bba35-24f6-42eb-bf2d-2cc33698d050] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Hi,&lt;/p&gt;&lt;p&gt;We are using Clearspace 2.0.3 (custom verison). I have found out that if I have a private community to which only certian users have access. And if I create a project in that community, this project is visible to even a non logged in user through the tags page. You basically go to the tags page. Click on the Projects radio button. Select the "Browse All Projects". This pops up a windows. In that window (the default search filter is All Communities) if you type in something that matches the project created in the private community, that community is listed.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Is this a hole in Clearspace security or this is how it is supposed to work? Any work arounds for this. Also are there any other places that have similar issues?&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Thanks,&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Atul&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:5b0bba35-24f6-42eb-bf2d-2cc33698d050] --&gt;</description>
      <pubDate>Fri, 07 Nov 2008 20:14:20 GMT</pubDate>
      <author>communities@jivesoftware.com</author>
      <guid>http://www.jivesoftware.com/jivespace/message/139914?tstart=0#139914</guid>
      <dc:date>2008-11-07T20:14:20Z</dc:date>
      <clearspace:dateToText>1 year, 2 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
    </item>
  </channel>
</rss>

