Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug] 编辑页面貌似可以不鉴权直接进入 #303

Open
OriyukiAkari opened this issue Jan 1, 2025 · 2 comments
Open

[Bug] 编辑页面貌似可以不鉴权直接进入 #303

OriyukiAkari opened this issue Jan 1, 2025 · 2 comments
Labels
bug Something isn't working PR welcome Good for new contributor

Comments

@OriyukiAkari
Copy link

Bug 描述

如题,测试了一下公开文章是可以进入的,私人文章阅读和修改都不行

复现步骤
将feed修改为writing即可

期望行为
希望能修改为Permission denied页

截图

image

环境变量

@OXeu OXeu added bug Something isn't working PR welcome Good for new contributor labels Jan 1, 2025
@ossplus
Copy link

ossplus commented Jan 8, 2025

Bug复现了;
但如果尝试Publish,会弹窗提示 Alert Permission denied

临时解决办法是用cf防火墙,限制网址writing的访问ip

@Izumiko
Copy link

Izumiko commented Feb 21, 2025

这个是不是也算不上bug?因为服务端本来就是返回文章的markdown源码,然后在客户端渲染。把feed改为writing只是用writing页面把未渲染的文章展示出来了而已。
发布的时候才会验证权限,然后也是按照预期弹出Permission denied。

应该算是用户交互方面优化不到位,不过正常用户也不会手动去改url为writing吧😂

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working PR welcome Good for new contributor
Projects
None yet
Development

No branches or pull requests

4 participants