Skip to:
Content

BuddyPress.org

Opened 6 years ago

Closed 6 years ago

#6835 closed defect (bug) (no action required)

[Bug] Banned users can post!

Reported by: davelr1 Owned by:
Milestone: Priority: normal
Severity: normal Version: 2.4.0
Component: Groups Keywords:
Cc:

Description

Hi!

My "bad" users just discovered that when a group admin kick/ban someone, the person can still post if they use the "go back" option on the browser.

Is guess buddypress only checks if the person is from that group when the form are generated... the post probably doesn't check if the person is member or not. The only way to a group admin make the banned user stop posting using this method is to close the topic for new replies.

As a site admin I can ban the user from the /wp-admin/user.php and this bug will not work. (but will ban the person from the whole site)

Did you guys know about this problem? Is there any temporary solution to make group admins ban users without having this trouble?

Found this bug using the most recent version of buddypress + bbpress and wordpress... also tried the alpha from bbpress... tried with different themes with only buddypress and bbpress as active plugins.

I also test with buddypress 2.2.3.1 and bbpress 2.5.7 (with wordpress 3.8).. so I guess this bug is present in all versions.

Thank you :)

Change History (2)

#1 @davelr1
6 years ago

  • Component changed from API to Component - Groups

#2 @r-a-y
6 years ago

  • Milestone Awaiting Review deleted
  • Resolution set to invalid
  • Status changed from new to closed

Thanks for reporting.

I just duplicated your problem and it is a bbPress issue since bbPress handles their BuddyPress integration into the BP Groups component.

I've reported the issue on bbPress Trac with a fix:
https://bbpress.trac.wordpress.org/ticket/2905

Marking as invalid.

Note: See TracTickets for help on using tickets.