This page is extremely disorganized. The user settings
such as staying private, etc should be put into a form,
not links in the page. It just needs help in general.
Discussion
Anonymous
-
2005-04-04
Logged In: YES
user_id=541183
The receive_emails flag needs to be exposed on this page as
well.
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
Anonymous
-
2005-07-10
Logged In: YES
user_id=541183
There is also a security problem. The functions that set
private/primary don't do any privilege checking. They don't
even check that the object belongs to the user who is logged in.
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
Logged In: YES
user_id=541183
The receive_emails flag needs to be exposed on this page as
well.
Logged In: YES
user_id=541183
There is also a security problem. The functions that set
private/primary don't do any privilege checking. They don't
even check that the object belongs to the user who is logged in.