Missing access check on gallery comment streams
The comment streams for per media gallery entries for group galleries is not having its create access checked to ensure the person commenting is a member of the group.
Updated by krileon almost 4 years ago
- Status changed from Assigned to Resolved
- % Done changed from 0 to 100
Multi-part fix. Requires improvements in CB Activity to handle a "parent" value for streams, which is the parent asset for the stream. The parent can then be checked for access permissions. This is fixed for all GJ comment streams requiring release of GJ, CB Activity, and CB Auto Actions. Note it will not be entirely fixed until CB Activity 5.0.0 is released.