MyBB Community Forums

Full Version: Posted Content Security
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
I think this might fall into the realm of a secuirty related design feature, but if you ask me, it counts as a bug with the current design :Smile... let me explain.

I have a forum tree branch on our installation, which is *(using the MyBot plugin to do so), setting all replies to an active thread as unapproved.
  • I know there are trolls and curious people, and I know others may want to 'help', so you are asking why?
    ---> Because we want to have an authorized Trivia Contest, ask a question, let members answer it! When the contest has elapsed, reveal the answers.
    • The same logic applies in general, when you want specific content to be moderated, and not revealed until a  moderator has reviewed it
This all said, the issue is that a member can "Subscribe" to the thread. And MyBB, will send them an email, with a snippet of the post. (thus, potentially revealing the answer, or in the security context, showing a member content that has not been reviewed).

I know I can disable subscriptions, but I dont want to do that. People should be able to subscribe to some threads, and I should be able to restrict subscriptions.

Now, mind you.... It makes sense that you might want people to subscribe, I agree! BUT.... bug.... if the message is not approved, why show a snippet of the message in an email message????

Thanks!