BuddyDev

Search

[Resolved] Users are able to message blocked and suspended users if you have the direct URL

  • Participant
    Level: Enlightened
    Posts: 72
    Nifty on #47786

    Hi,

    This relates to the BuddyPress Moderation Tools plugin and the included BuddyPress Block Users Plugin.

    If a user has the direct compose new message URL for a suspended user, then it is possible for them to send a new message to a suspended user.

    The same is true when a blocked user tries to contact the blocker, or when the blocker tries to contact the blocked user; it is still possible to start a new thread if you have the direct profile URL with the compose portion included (e.g. /members/myprofileurlhere/messages/compose/?r=profiletomessagehere&_wpnonce=<wpnoncegoeshere> or /members/myprofileurlhere/messages/compose/?r=profiletomessagehere).

    In all of the above situations, the user will get notified about the message in a notification email (assuming they have email notifications on).

    We are using BuddyPress 10.6.0 and using the Legacy Template Pack.

    Thanks.

  • Keymaster
    (BuddyDev Team)
    Posts: 24706
    Brajesh Singh on #47801

    Hi,
    Thank you for reporting the issue.
    Please allow us to test it. This should not work. If it is, It could be a bug. We will test and conform you on/after Monday.

    Thank you
    Brajesh

  • Participant
    Level: Enlightened
    Posts: 72
    Nifty on #47807

    Hi Brajesh,

    We’ve done some further testing, and believe the issue is related to the “BuddyPress Private Message Rate Limiter” plugin, which we also have running. When this plugin is turned off, a blocked or suspended user cannot be messaged via the direct compose new message URL.

    All three plugins are up to date. We’ve tested it on an install which is only running these plugins and BuddyPress, with a default theme.

    Thanks.

  • Keymaster
    (BuddyDev Team)
    Posts: 24706
    Brajesh Singh on #47821

    Hi,
    Thank you for the detail.


    @ravisharma
    will be assisting you with it.

    Regards
    Brajesh

  • Keymaster
    Level: Yogi
    (BuddyDev Team)
    Posts: 3115
    Ravi on #47823

    Hello Nifty,

    I have tried to create this issue on my development server but I am unable to create this. Can you please share a short video of the issue and how are you creating this so that I can check then fix it.

    Regards
    Ravi

  • Participant
    Level: Enlightened
    Posts: 72
    Nifty on #47824

    Hi Ravi,

    Thanks for looking into this. We can’t take a short video right now unfortunately, but have linked some screenshots of the settings we have in each of the plugins below.

    https://snipboard.io/sQJGMp.jpg
    https://snipboard.io/dHhlUx.jpg
    https://snipboard.io/ZFcYma.jpg
    https://snipboard.io/mWwcTy.jpg

    We’re using the Legacy Template Pack, as mentioned above, but with further testing have also noted that this is not an issue with the Nouveau Template Pack.

    Please let us know if there’s anything else we can provide to assist.

    Thank you.

  • Keymaster
    Level: Yogi
    (BuddyDev Team)
    Posts: 3115
    Ravi on #47825

    Hello Nifty,

    Thank you for sharing the screenshots. I will check it again and will update you soon.

    Regards
    Ravi

  • Keymaster
    Level: Yogi
    (BuddyDev Team)
    Posts: 3115
    Ravi on #47830

    Hello Nifty,

    You are right with legacy both blocker and blocked user can start new conversation with each other. I am going to fix this today and will update you soon.

    Regards
    Ravi

  • Participant
    Level: Enlightened
    Posts: 72
    Nifty on #47841

    Thanks, Ravi. Will the fix also apply to suspended users?

  • Keymaster
    Level: Yogi
    (BuddyDev Team)
    Posts: 3115
    Ravi on #47860

    Hello Nifty,

    Sorry for the delayed reply. I have updated the plugin BP Private Message Rate Limiter and BuddyPress Block Users please upgrade and give it a try.

    Regards
    Ravi

You must be logged in to reply to this topic.

This topic is: resolved