WordPress.org

Make WordPress Core

Opened 16 months ago

Last modified 4 weeks ago

#46968 reviewing enhancement

Editors can't search for private posts through Search widget

Reported by: cecilerainon Owned by:
Milestone: Future Release Priority: normal
Severity: normal Version:
Component: Query Keywords: 2nd-opinion has-patch needs-refresh
Focuses: Cc:

Description

When a user is an Editor, they can't search for other users' private posts through the Search widget on the front end. However, they can see these posts in WP Admin or on the author's archive page (site.com/author/username). I would expect this behavior to be either or but not a mix of the two.

To reproduce:

  • Have a site with the core Search widget added to either the sidebar or footer.
  • As an Administrator, publish and set a post to private.
  • Connect to the Editor’s account and do the following to witness the inconsistency:

Tested on WordPress 5.1.1 sites. This happens regardless of the browser or theme, with or without plugins, and with or without Jetpack activated.

Change History (7)

#1 @audrasjb
15 months ago

  • Keywords needs-patch added
  • Owner set to audrasjb
  • Status changed from new to reviewing

Hi @cecilerainon, welcome to WordPress Core Trac and… "merci pour le ticket" :-)

Auto-assigning the ticket for review.

Cheers,
Jb

Version 0, edited 15 months ago by audrasjb (next)

#2 @audrasjb
4 months ago

  • Milestone changed from Awaiting Review to 5.5
  • Severity changed from minor to normal
  • Version 5.1.1 deleted

#3 @audrasjb
4 months ago

  • Component changed from Widgets to Query

After having a deeper look on the issue, it appears that it's not related to the search widget but to the general search query.

Moving the ticket to Query component.

#4 @audrasjb
4 months ago

  • Keywords 2nd-opinion added
  • Owner audrasjb deleted
  • Type changed from defect (bug) to enhancement

#5 @whyisjake
2 months ago

Like @audrasjb mentioned, private posts shouldn't be showing up in a query like this. Thinking this is a wontfix but open to other ideas.

#6 @samful
2 months ago

  • Keywords has-patch needs-refresh added; needs-patch removed

I debugged this myself and came across the same “current_user_can( "read_private_anys" )” issue as inbytesinc did 10 years ago. I believe the fix in 13509 (https://core.trac.wordpress.org/ticket/13509) needs to be tested and committed to fix this issue.

If it helps, I also found another fix for this issue here: https://wordpress.stackexchange.com/questions/110569/private-posts-pages-search

@whyisjake please look at ticket 13509 as there definitely seems to an issue with that IF statement and this issue has been around for 10 years by the look of it :(

I believe @cecilerainon is correct here and WordPress should be working in the way she expects.

#7 @davidbaumwald
4 weeks ago

  • Milestone changed from 5.5 to Future Release

With 5.5 Beta 1 releasing tomorrow, this is being moved to Future Release. If any maintainer or committer feels the remainder of this ticket can be resolved in time, or wishes to assume ownership during a specific cycle, feel free to update the milestone accordingly.

Note: See TracTickets for help on using tickets.