[#2913] Hidden profiles can be guessed and pulled via url

12 years 6 months ago - 12 years 6 months ago #179830 by ignatius2
Thanks Kyle,

I was able to save the action but for some reason this particular action does not work (in FF 3.6xx). I downloaded and installed 1.0.2 but this produces the same result. I am not redirected when trying to get to a profile that I should be redirected away from, based on a CB custom field.

I do not see the message when trying to get to a forbidden profile.

When after running tests I was able to see the message, it was listed 24 times rather than only ounce.

I tried to redirect to my-profile, index.php?option=com_comprofiler, or even %20index.php?option=com_comprofiler. Nothing works.

The expression you gave me is:

[cb:userdata field="cb_myfield" user="#displayed" /]
Equal To
[cb:userdata field="cb_myfield" user="#me" /]

Could this be failing because I am using Joomla SEF?

Note that if I replace the field I selected with a field that does not exist, I get into a loop and receive the following error message:

"The page isn't redirecting properly
Firefox has detected that the server is redirecting the request for this address in a way that will never complete.
This problem can sometimes be caused by disabling or refusing to accept cookies."

Thanks

John

Please Log in to join the conversation.

12 years 6 months ago - 12 years 6 months ago #179838 by krileon
Your trigger is a trigger executed on all profiles and your redirect is to your own profile. You've effectively created an infinite loop. The condition maybe incorrect and is for you to re-test and debug accordingly as I can not guarantee how your fields will behave or output. The best way to test is to create a delimiter field then put your substitutions in it and see if they output as you would expect and if not adjust as necessary. The plugin is confirmed working fine and so is the redirect, but is just your condition that is failing.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

12 years 6 months ago - 12 years 6 months ago #179849 by ignatius2
Thanks a lot Kyle,

It works :woohoo:

John

Please Log in to join the conversation.

12 years 6 months ago - 12 years 6 months ago #180032 by ignatius2
Oooops FYI, it seems that I found something else... it seems that the exclude option at the bottom of the action form does not seem to work. No rush from my perspective, I do not need that feature yet.

Thanks

John

Please Log in to join the conversation.

12 years 6 months ago #180097 by krileon
For exclude to work you need to specify a comma separated list of userids (e.g. 62,97,130).


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

12 years 6 months ago #180098 by ignatius2
Of course, I did. I tried with 62 and it did not work. Should I have tried with "62,"?

Thanks

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.191 seconds

Facebook Twitter LinkedIn