Skip to content

Fix - Restrict privacy modification on media and album edit - #2378

Merged
Intenzi merged 1 commit into
developfrom
fix/edit-privacy-permissions
Oct 6, 2026
Merged

Intenzi merged 1 commit into
developfrom
fix/edit-privacy-permissions

Conversation

@Intenzi

@Intenzi Intenzi commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Prevents updating privacy on single media and album edit requests when the privacy field is not available in the UI.

Changes

  1. Single Media Edit (RTMediaTemplate::save_single_edit()):

    • Drops $_POST['privacy'] if editing group media, moderated media (privacy == 80) and when user privacy override is disabled.
    • Only includes privacy in $data_array if $_POST['privacy'] is present and allowed.
    • Reason: The frontend edit template hides the privacy dropdown for group media (which inherits group privacy) and moderated media (to prevent users from unflagging their own content). The backend accepts privacy unconditionally in POST requests presently.
  2. Album Edit (RTMediaTemplate::save_album_edit()):

    • Removed privacy from $data_array and unsets $_POST['privacy'].
    • Reason: album-single-edit.php does not have a privacy field in the frontend. Submitting privacy in POST should not modify the album's privacy.

@Intenzi
Intenzi requested a review from the-hercules October 6, 2026 09:39
@Intenzi Intenzi self-assigned this Oct 6, 2026
@rtBot

rtBot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Unable to PHPCS or SVG scan one or more files due to error running PHPCS/SVG scanner:

  • app/main/controllers/template/RTMediaTemplate.php

The error may be temporary. If the error persists, please contact a human (commit-ID: 9751781).

@Intenzi Intenzi mentioned this pull request Oct 6, 2026
@Intenzi
Intenzi merged commit 9e4ddc6 into develop Oct 6, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants