Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsBlogBlogBlog Security problemBlog Security problem
Previous
 
Next
New Post
6/18/2007 12:08 AM
 

I'm not sure whether the question has been raised before becuase my network to access this site is a little bit slow.  The problem is:

When I setup a blog with "Make this blog public" "Allow users to post comments" unchecked, then add a entry into this blog with "Publised" and "Allow users to comment on this entry" unchecked, normal users and unregistered users will not able to see this blog nor the entry in the View_Blog module.  However anybody can easily see these private entry access the URL and change EntryID.  

I think this is a security issue because some users don't want others to see some of his blog.  May there are some configurations I haven't found which can improve the security.  Since I'm only a system user not a developer, I have no idea how to resolve this trouble.  Please check whether this is a bug or not. 

Thanks for attention.

 
New Post
6/18/2007 8:36 AM
 

thank you for raising this, i will discuss this with the blog team.

Cathal


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
6/18/2007 9:15 AM
 

czhang,

what version of the blog are you using?

There is a ticket in gemini is related to this issue http://support.dotnetnuke.com/issue/ViewIssue.aspx?id=4034
It is planned for the next release (03.04.00) - I will keep you guys updated on the developments.

Thanks!


Maxiom TechnologyAntonio Chagoury | Microsoft MVP
Maxiom Technology
Professional .net & DotNetNuke Solutions
web: www.maxiomtech.com
blog: www.cto20.com
twitter: @antoniochagoury & @maxiomtech

 
New Post
6/18/2007 9:42 AM
 

I have once tried to submit issue to support site but I have no privilege to do that.  Here list my configuration:

Windows 2003 Web edition, SP2, With .NET 2.0 installed
SQL 2005 Express 9.0.3042
DNN 4.5.3
Blog 3.3.0

Honestly I really wish to see new version Blog with more friendly features.  Such as "Previous Entry","Next Entry".

 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsBlogBlogBlog Security problemBlog Security problem


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out