gitty icon indicating copy to clipboard operation
gitty copied to clipboard

Filter feed items by reading access

Open christydennison opened this issue 12 years ago • 2 comments

Feed items are not filtered by reading access, so a user could potentially see feed items for a profile that the user should not be able to see.

christydennison avatar Apr 19 '12 04:04 christydennison

I think the right way to solve this is to filter all shown feed comments by subject.can_read?(user). This involves (1) making sure that all possible subjects implement can_read? and (2) dealing with the fact that if we want to display 100 items, we might need to pull a lot more from the db.

pwnall avatar Apr 19 '12 04:04 pwnall

I'll think about this for a while, and see if I can come up with a better solution.

pwnall avatar Apr 19 '12 04:04 pwnall