Restrict access to track user page by default in Tracker module

Created on 2 August 2016, almost 8 years ago
Updated 22 April 2024, 2 months ago

Tracker module allows any user to access /user/%uid/track pages by default.

That might be a potentially problem if content associated to user being tracked isn't in control or has the properly permissions, so sensitive content could be accesed easily in Track tab from a profile page.

Search engines show this link by default and allows access. A common SEO problem on Drupal sites is that search engines will index URL parameters that should not be indexed as /tracker or /user/*/track pages.

I attach this patch to limit theses access only for administrators and users who match with the tracking page being accessed (users are able to view their own Track activity).

I don't now if this is a valid approach, by anyway, thanks for your feedback.

πŸ“Œ Task
Status

Active

Version

1.0

Component
TrackerΒ  β†’

Last updated 26 days ago

No maintainer
Created by

πŸ‡ͺπŸ‡ΈSpain mercalia

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.69.0 2024