Make WordPress Core

Opened 20 years ago

Closed 18 years ago

Last modified 3 years ago

#1078 closed defect (bug) (invalid)

Atom feed including private post info

Reported by: anonymousbugger's profile anonymousbugger Owned by:
Milestone: Priority: normal
Severity: minor Version: 1.5.1
Component: General Keywords:
Focuses: Cc:

Description

Typed my url in plus /atom and a file was downloaded. In it the info from my private posts was included. My private posts are generally to do lists or other useless things that only make sense to me. I am using 1.5 not 1.5.1.

Thanks
terral@…

Attachments (1)

atom (10.8 KB) - added by anonymousbugger 19 years ago.

Download all attachments as: .zip

Change History (4)

#1 @anonymousbugger
20 years ago

  • Patch set to No

#2 @coffee2code
20 years ago

I don't believe this is a bug.

If you, as the admin/post author, have previously viewed the passworded protected post(s) in your browser, then a cookie has been stored in the browser which indicates you are allowed to view the contents of the post, even when viewing the feed through the browser.

To verify this for yourself, you can:

a.) create a new passworded post. Do NOT type in the password for the post once it has been published. View the feed. You should not see the post's contents.

-or-

b.) view the feed in another browser or an RSS feed reader. You should not see the post's contents.

@anonymousbugger
19 years ago

#3 @filosofo
18 years ago

  • Resolution set to invalid
  • Status changed from new to closed

Invalid at least by or before 2.0.3.

Note: See TracTickets for help on using tickets.