← Back to team overview

mahara-contributors team mailing list archive

[Bug 1778481] Re: Page not on watchlist shown in watchlist notification email with author name

 

Hi Kristina,

That is the problem - this person did not even have access to the page
that was showing on their watchlist. So the bug disclosed personal
information (the name of a person, who was not and should not have been
known to them that was on the page "by firstname lastname ").

To provide a bit more information. The page that was shown on the
watchlist was an automatic copy created for the user upon registration
to an institution. The settings for the institution allow copying of the
collection for all new users, but no other sharing of the collection is
set at institutional level. The person who saw the page on the watchlist
is a member of a different institution and neither has staff, or admin
privileges in the institution that they are a member or in the
institution to which the copied collection belonged. Having checked the
page itself it was not manually shared in any way with the person who
could see it on their watchlist.

I thought that I would provide this extra information in case it helps,
but due to the GDPR implications of this bug it is big deal for us. We
cannot even discourage use of the watchlist as this page showed up on
the list without any user intervention.

Any help is greatly appreciated,

Fiona

-- 
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: Subscription for all Mahara Contributors -- please ask on #mahara-dev or mahara.org forum before editing or unsubscribing it!
https://bugs.launchpad.net/bugs/1778481

Title:
  Page not on watchlist shown in watchlist notification email with
  author name

Status in Mahara:
  Incomplete

Bug description:
  A page not accessible to the user and not on that user's watchlist is
  shown as "changed" in the watchlist notification email.

  Version of Mahara: 18.04.1
  Operating system: All - specific to watchlist emails
  Database: MySQL
  Browser and version: N/A

To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/1778481/+subscriptions


References