This Question is Possibly Answered

1 "correct" answer available (4 pts) 2 "helpful" answers available (2 pts)
Related Product Enhancement/Bug IDs: CS-9863
1 Replies Last post: Nov 17, 2008 8:15 AM by Long Ton That  
Atul Kshatriya Novice 153 posts since
Jun 30, 2008
Currently Being Moderated

Nov 7, 2008 12:14 PM

can see projects in private communities without logging in

Hi,

We are using Clearspace 2.0.3 (custom verison). I have found out that if I have a private community to which only certian users have access. And if I create a project in that community, this project is visible to even a non logged in user through the tags page. You basically go to the tags page. Click on the Projects radio button. Select the "Browse All Projects". This pops up a windows. In that window (the default search filter is All Communities) if you type in something that matches the project created in the private community, that community is listed.

 

Is this a hole in Clearspace security or this is how it is supposed to work? Any work arounds for this. Also are there any other places that have similar issues?

 

Thanks,

 

Atul

Long Ton That JiveSupport 3,280 posts since
Apr 1, 2008
Currently Being Moderated
Nov 17, 2008 8:15 AM in response to: Atul Kshatriya
Re: can see projects in private communities without logging in

Hey Atul,

I'm going to close this ticket as it has already been addressed in your private support portal thread. Here was the findings for anyone that is having similar issues:

 

 

I verified that hidden projects are exposed in searchs, for example going to Browse > Projects > Search "project name" will return the project's name, community and end date.

 

In my testing, I found user's can only see the projects listed in the search results, they cannot actually view the project or it's contents. Doing so will return an "unauthorized" error.

 

This appears to be resolved in Clearspace 2.5.X but is still an issue in Clearspace 2.0.9, I've gone ahead and filed a bug for this: CS-9863. One of our developers will look into this further and resolve it in a future release of Clearspace 2.0.X... let me know if there's anything else I can add to this ticket or if you have any additional questions or concerns.





~Long

More Like This

  • Retrieving data ...
To better serve our customers we have included functionality to automatically follow up on a case after it has been idle for more than 5 days, and then auto close after an additional 3 days of inactivity. Choose No to acknowledge that this case will remain idle for longer than 5 days.