]> git.mxchange.org Git - quix0rs-gnu-social.git/commitdiff
Possible hack for tags from private dents in public profile or wrong scope (both...
authorRoland Haeder <roland@mxchange.org>
Fri, 27 Mar 2015 22:16:34 +0000 (23:16 +0100)
committerRoland Haeder <roland@mxchange.org>
Fri, 27 Mar 2015 22:16:34 +0000 (23:16 +0100)
Signed-off-by: Roland Haeder <roland@mxchange.org>
actions/publictagcloud.php

index 6d0d4237e9d74ce1788863f43eeb9ed14603d96c..1f169cfc5f71afe7ca462491e689989aa0615319 100644 (file)
@@ -110,6 +110,8 @@ class PublictagcloudAction extends Action
          */
         $tags->selectAdd();
         $tags->selectAdd('tag');
+        $tags->selectAdd('notice_id');
+        $tags->selectAdd('scope');
 
         // Add the aggregated columns...
         $tags->selectAdd('max(notice_id) as last_notice_id');
@@ -117,6 +119,7 @@ class PublictagcloudAction extends Action
         $cutoff = sprintf("notice_tag.created > '%s'",
                           common_sql_date(time() - common_config('tag', 'cutoff')));
         $tags->selectAdd($calc . ' as weight');
+        $tags->joinAdd(array('notice_id', 'notice:id'));
         $tags->whereAdd($cutoff);
         $tags->groupBy('tag');
         $tags->orderBy('weight DESC');
@@ -132,6 +135,28 @@ class PublictagcloudAction extends Action
             $tw = array();
             $sum = 0;
             while ($tags->fetch()) {
+                // Check scope:
+
+                // 1) Get notice object and set id
+                $notice = new Notice();
+                $notice->id    = $tags->notice_id;
+                $notice->scope = $tags->scope;
+
+                // Is it private scope?
+                if ($notice->isPrivateScope()) {
+                    // 2) Get current profile
+                    $profile = Profile::current();
+
+                    // Is the profile not set?
+                    if (!$profile instanceof Profile) {
+                        // Public viewer shall not see a tag from a private dent (privacy leak)
+                        continue;
+                    } elseif (!$notice->inScope($profile)) {
+                        // Current profile is not in scope (not allowed to see) of notice
+                        continue;
+                    }
+                }
+
                 $tw[$tags->tag] = $tags->weight;
                 $sum += $tags->weight;
             }