Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-65169

Messaging: search should respect profile visibility when site-wide messaging is used

    XMLWordPrintable

    Details

      Description

      At present, this returns all users, leaking the names of those who are not otherwise visible to the searcher.

      To replicate:

      1. Enable site wide messaging (site admin -> messaging -> messaging settings -> messagingallusers)
      2. Create some users on the site.
      3. Enrol a user (student 1) as a student in course 1
      4. Enrol another user (student 2) as a student in course 2
      5. As student 1, search for student 2.
      6. Notice you can see them in the search results. You should not be able to, given their profile is not visible to you anywhere. You can confirm this by trying to view their profile either at course or site level.

        Attachments

          Issue Links

            Activity

              People

              • Assignee:
                jaked Jake Dallimore
                Reporter:
                jaked Jake Dallimore
                Peer reviewer:
                Mark Nelson
                Integrator:
                Sara Arjona (@sarjona)
                Tester:
                CiBoT
                Participants:
                Component watchers:
                Jake Dallimore, Jun Pataleta, Ryan Wyllie
              • Votes:
                3 Vote for this issue
                Watchers:
                7 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:
                  Fix Release Date:
                  13/May/19

                  Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 1 day, 4 hours
                  1d 4h