After logout, users see (even hidden) contents

Get help with installation and running phpBB 3.2.x here. Please do not post bug reports, feature requests, or extension related questions here.
Unweliath
Registered User
Posts: 45
Joined: Sat Jan 14, 2017 5:25 pm

After logout, users see (even hidden) contents

Post by Unweliath »

Support Request Template
What version of phpBB are you using? phpBB 3.2.0
What is your board's URL? http://confidential
Who do you host your board with? Hosteurope
How did you install your board? I used the download package from phpBB.com
What is the most recent action performed on your board? Update from a previous version of phpBB3
Is registration required to reproduce this issue? Yes
Do you have any MODs installed? No
Do you have any extensions installed? Yes
What version of phpBB3 did you update from? phpBB 3.1.10
What extensions do you have installed? About us
Ajax Chat
Board Announcements
Digests
Feed Reader
Groups on Registration
Remind username
Reputation System
Simple mentions
Tapatalk Plugin for phpBB 3.1/3.2
Usermap
What styles do you currently have installed? standard styles
What language(s) is your board currently using? de_x_sie (German)
Which database type/version are you using? MySQL 5
What is your level of experience? Comfortable with PHP and phpBB
What username can be used to view this issue? No answer given
What password can be used to view this issue? No answer given
What actions did you take (updating your board; installing a MOD, style or extension; etc.) prior to this problem becoming noticeable? Purging the cache
Please describe your problem. I have a problem I wasn't able to solve so far: My users sporadically experience that after logging out, they see forum contents. After refresh or clicking on any link they are finally logged out for good. So far this is not nice, but acceptable. But in those cases they can also see a board which is only readable for Administrators - and this is freaking me out. One user even sent me a screenshot: He was on the "unread posts" page and logged out -> after that he was also able to see the unread posts from the Admin board!

First I thought it is a browser issue caching some contents. But the client's browser never should get content the users are not allowed to see!

I already flushed the Cache multiple times, which seems not to help. The issue is not appearing regularly and myself I only had it once for now.

Any suggestions out there? Is this a known issue? How could I debug this (considering the sporadicality...)
Generated by SRT Generator
User avatar
david63
Registered User
Posts: 20646
Joined: Thu Dec 19, 2002 8:08 am

Re: After logout, users see (even hidden) contents

Post by david63 »

Does your site use Cloudflare or some other caching system? This type of problem has been reported previously where a caching system has been in use.
David
Remember: You only know what you know and - you don't know what you don't know!

I now no longer support any of my extensions but they will start to become available here
Unweliath
Registered User
Posts: 45
Joined: Sat Jan 14, 2017 5:25 pm

Re: After logout, users see (even hidden) contents

Post by Unweliath »

Good point. No, not at all, i run a "pure" installation on php 7.0.23
User avatar
Steve
Registered User
Posts: 1481
Joined: Tue Apr 07, 2009 7:48 pm
Name: Steven Clark
Contact:

Re: After logout, users see (even hidden) contents

Post by Steve »

Whys your site "confidential"? Try disabling tapatalk extension.
@ The Chief Medical Officers guideline for men is that: You are safest not to drink regularly more than 14 units per week.
- I drank that today++ :lol: 🍺
Unweliath
Registered User
Posts: 45
Joined: Sat Jan 14, 2017 5:25 pm

Re: After logout, users see (even hidden) contents

Post by Unweliath »

Steve wrote: Thu Sep 21, 2017 7:16 am Whys your site "confidential"?
I just don't like to spread the URL all over the internet :D If its really needed to solve the issue, I can give it to you, though
Steve wrote: Thu Sep 21, 2017 7:16 am Try disabling tapatalk extension.
Hm good point, never thought about that. But that will disconnect a lot of my users using smartphones...
User avatar
Steve
Registered User
Posts: 1481
Joined: Tue Apr 07, 2009 7:48 pm
Name: Steven Clark
Contact:

Re: After logout, users see (even hidden) contents

Post by Steve »

Disabling your extensions will indicate if it's a problem with the extensions or the phpBB software. i use my mobile with out tapatalk just fine 😬
@ The Chief Medical Officers guideline for men is that: You are safest not to drink regularly more than 14 units per week.
- I drank that today++ :lol: 🍺
Unweliath
Registered User
Posts: 45
Joined: Sat Jan 14, 2017 5:25 pm

Re: After logout, users see (even hidden) contents

Post by Unweliath »

Steve wrote: Thu Sep 21, 2017 9:00 am Disabling your extensions will indicate if it's a problem with the extensions or the phpBB software. i use my mobile with out tapatalk just fine 😬
Yeah, problem is that the issue is reported 1-2 times per month. I cannot turn off all extensions for such a long time :oops:
User avatar
stevemaury
Support Team Member
Support Team Member
Posts: 52768
Joined: Thu Nov 02, 2006 12:21 am
Location: The U.P.
Name: Steve
Contact:

Re: After logout, users see (even hidden) contents

Post by stevemaury »

Why do you think you need TapaTalk?
I can stop all your spam. I can upgrade or update your Board. PM or email me. (Paid support)
Unweliath
Registered User
Posts: 45
Joined: Sat Jan 14, 2017 5:25 pm

Re: After logout, users see (even hidden) contents

Post by Unweliath »

My users like it. But ok, I think I will try without that.
Unweliath
Registered User
Posts: 45
Joined: Sat Jan 14, 2017 5:25 pm

Re: After logout, users see (even hidden) contents

Post by Unweliath »

After having Tapatalk disabled for one month, today two users reported again the occurence of the bug. One posted a screenshot of the „unread topics page“ with topics from the Admin-only board!
Unweliath
Registered User
Posts: 45
Joined: Sat Jan 14, 2017 5:25 pm

Re: After logout, users see (even hidden) contents

Post by Unweliath »

Today, a normal user again posted a screenshot of his browser showing the admin-only boards. After a refresh he says its gone. Tapatalk is still disabled.

Anyone has an idea what the heck is going on?
User avatar
thecoalman
Community Team Member
Community Team Member
Posts: 5885
Joined: Wed Dec 22, 2004 3:52 am
Location: Pennsylvania, U.S.A.
Contact:

Re: After logout, users see (even hidden) contents

Post by thecoalman »

You sure the permissions are set right?

Easiest way to exclude a group from forum is just not add the group.

Permissions tab >> forum permissions >> Pick a forum(s) >> Under manage groups simply remove the group
“Results! Why, man, I have gotten a lot of results! I have found several thousand things that won’t work.”

Attributed - Thomas Edison
User avatar
KevC
Support Team Member
Support Team Member
Posts: 72375
Joined: Fri Jun 04, 2004 10:44 am
Location: Oxford, UK
Contact:

Re: After logout, users see (even hidden) contents

Post by KevC »

Have you logged out, or do you have a separate 'normal' account that you can test to see if you can see the same?
Has the person who sent you the screenshot got their username in view so you can check that it is indeed their account?
-:|:- Support Request Template -:|:-
Image
"Step up to red alert. Sir, are you absolutely sure? It does mean changing the bulb"
Unweliath
Registered User
Posts: 45
Joined: Sat Jan 14, 2017 5:25 pm

Re: After logout, users see (even hidden) contents

Post by Unweliath »

thecoalman wrote: Tue Dec 26, 2017 2:40 pm You sure the permissions are set right?

Easiest way to exclude a group from forum is just not add the group.

Permissions tab >> forum permissions >> Pick a forum(s) >> Under manage groups simply remove the group
This I checked multiple times. Only administrators and global moderators have access to this forum. Even if it would be set in a wrong way, it should then be always visible to the users, not sporadically.
Unweliath
Registered User
Posts: 45
Joined: Sat Jan 14, 2017 5:25 pm

Re: After logout, users see (even hidden) contents

Post by Unweliath »

KevC wrote: Tue Dec 26, 2017 3:01 pm Have you logged out, or do you have a separate 'normal' account that you can test to see if you can see the same?
I have a test account with same rights as my normal users, but I cannot see the issue. However, also my normal users see it only once in a while. What should I trace/check when I would experience the issue? Server logs?
KevC wrote: Tue Dec 26, 2017 3:01 pm Has the person who sent you the screenshot got their username in view so you can check that it is indeed their account?
Yes, I know the user. He is a normal user without admin or moderator privileges. Same as the other users who reported the issue.
Post Reply

Return to “[3.2.x] Support Forum”