Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-64048

Users can send contact requests to unauthorised contacts

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Deferred
    • Icon: Minor Minor
    • None
    • 3.6.3, 3.7
    • Messages
    • 1
    • Sprint 5 - Sander's special

      If a user can see a conversation with another user, but they cannot message nor add the other user as a contact, this produces a couple of bugs in the interface.

      To replicate in 3.6/3.7:

      1. Have a site with an admin and at least one other user (user1), where the admin is not enrolled in any course with user1.
      2. Log in as admin.
      3. Set Site administration Advanced features > messagingallusers = disabled (in 3.7 this is found in Site administration > Messaging > Messaging settings).
      4. Open messages menu and set the admin to accept "my contacts only".
      5. Send a message to user1.
      6. Log in as user1.
      7. Open the message from the admin.
      8. Bug: The user is given the option to send a contact request.

      Correction:

      1. Though attempting to send the request will return an error at step 8, the send box should have the "You are unable to message this user" dialogue, which is used in other cases, rather than allowing the attempt in the first place.

       

       

            Unassigned Unassigned
            michaelh Michael Hawkins
            Votes:
            9 Vote for this issue
            Watchers:
            11 Start watching this issue

              Created:
              Updated:
              Resolved:

                Error rendering 'clockify-timesheets-time-tracking-reports:timer-sidebar'. Please contact your Jira administrators.