Uploaded image for project: 'CiviCRM'
  1. CiviCRM
  2. CRM-8389

View Mail in Browser permalinks give access to all mailings regardless of visibility settings

    Details

    • Type: Bug
    • Status: Done/Fixed
    • Priority: Trivial
    • Resolution: Fixed/Completed
    • Affects Version/s: 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.4.4, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4
    • Fix Version/s: 3.4.5
    • Component/s: None
    • Labels:
      None

      Description

      The "visibility" setting for CiviMail mailings seems to have no effect.

      Permalinks to CiviCRM mailings use the URL format
      http://[domain.tld]/civicrm/mailing/view/?id=X&reset=1
      where X is the mailing ID.

      Issue: even when the "visibility" of a mailing X is set to "User and User Admin Only", CiviCRM serves up a page displaying the mailing in response to the above URL.

      Unless the "visibility" of a mailing is set to "Public Pages", the above URL should result in an "access denied" message.

        Attachments

          Activity

            People

            • Assignee:
              lobo Donald A. Lobo
              Reporter:
              noah Noah Miller
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: