This topic contains a post which is marked as Best Answer. Press here if you would like to see it.
*

oscman

  • ****
  • 227 posts
Security flow
« on: March 26, 2017, 03:00:31 PM »
Hello, anyone with a link can see a message without loging in, i am trying to reproduce it on demo but i can't.
Did you make any fix for this recently?
on my site this link would show messages of the treat without redirecting to login https://veronika.mb-themes.com/im-messages/37/k7t9lPq4TO

*

MB Themes

Re: Security flow
« Reply #1 on: March 26, 2017, 08:03:44 PM »
@oscman
You have secret key in URL specific for each thread.
  To get fast support, we need following details: Detail description, URL to reproduce problem, Screenshots

*

oscman

  • ****
  • 227 posts
Re: Security flow
« Reply #2 on: March 27, 2017, 03:23:02 PM »
yes but on demo it will require you to login if you are not the owner

*

MB Themes

Re: Security flow
« Reply #3 on: March 27, 2017, 03:48:43 PM »
@oscman
This can be set in plugin settings, if user must be logged or no.
  To get fast support, we need following details: Detail description, URL to reproduce problem, Screenshots

*

oscman

  • ****
  • 227 posts
Re: Security flow
« Reply #4 on: March 28, 2017, 12:13:35 PM »
ofcourse i have set it but it still doesn't ask if u have the link

*

MB Themes

Re: Security flow
« Reply #5 on: March 28, 2017, 12:46:35 PM »
@oscman
Ok, that is bad or good?
Not sure what is your point.
  To get fast support, we need following details: Detail description, URL to reproduce problem, Screenshots

*

oscman

  • ****
  • 227 posts
Re: Security flow
« Reply #6 on: March 28, 2017, 06:20:21 PM »
i am not sure :P maybe someone could exploit this and see private conversations by trying random links or something?

Marked as best answer by oscman on March 29, 2017, 01:56:29 PM
*

MB Themes

Re: Security flow
« Reply #7 on: March 28, 2017, 06:37:45 PM »
@oscman
There is higher chance to win lottery then find combination of 8 numeric and alphabethic characters :)
  To get fast support, we need following details: Detail description, URL to reproduce problem, Screenshots