Restrict access to track user page by default in Tracker module

Created on 2 August 2016, over 8 years ago
Updated 22 April 2024, 12 months ago

Tracker module allows any user to access /user/%uid/track pages by default.

That might be a potentially problem if content associated to user being tracked isn't in control or has the properly permissions, so sensitive content could be accesed easily in Track tab from a profile page.

Search engines show this link by default and allows access. A common SEO problem on Drupal sites is that search engines will index URL parameters that should not be indexed as /tracker or /user/*/track pages.

I attach this patch to limit theses access only for administrators and users who match with the tracking page being accessed (users are able to view their own Track activity).

I don't now if this is a valid approach, by anyway, thanks for your feedback.

📌 Task
Status

Active

Version

1.0

Component
Tracker 

Last updated 20 days ago

No maintainer
Created by

🇪🇸Spain mercalia

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024