Permissions Issue: Author can view articles they have no permissions for | World Anvil

Remove these ads. Join the Worldbuilders Guild

Permissions Issue: Author can view articles they have no permissions for

closed
· Access management (subscribers/authors) ·
By wags08 on 01/07/2024

Making another user a writer in a world allows them to go to the article list page (/world/athena) via the URL. Here they are able to view every article even those they have no permission to.   Expected: Either authors of Writer or Editor rank should still only have access the the articles they've been granted permission to or they could be blocked from the athena page entirely.

Steps to Reproduce

Steps: 1) Make another user an author of type rank Writer. 2) As the writer navigate to the dashboard for the world. 3) As the writer navigate via the url to worldanvil.com/world/athena. 4) The writer can now see and read every article - though trying to open one will give a security error.

Operating System

Windows

Browser

Google Chrome