Welcome to all phpBB2 Refugees!This site is intended to continue support for the legacy 2.x line of the phpBB2 bulletin board package. If you are a fan of phpBB2, please, by all means register, post, and help us out by offering your suggestions. We are primarily a community and support network. Our secondary goal is to provide a phpBB2 MOD Author and Styles area.
Posted: Sun Nov 13, 2016 8:26 am Post subject: Fix the blog mod by hyperion
It turned out that if a guest can post comments Blog Entry, and then he can edit all replicas in this blog, on a link at the end of http://saite.ru/forum/weblog_posting.php?mode=editreply&r=1234
digits at the end - id post
You can edit posts require authorization. Suffice it to log in go to this link, and edit the message before sending log out.
Code:
OPEN
weblog_posting.php
FIND
// If the user isn't the original poster or a contributor or the weblog owner...
If it is simple in line
if ( $reply_data['poster_id'] != $userdata['user_id'] && !$contributor && $weblog_data['weblog_id'] != $userdata['user_id'] && $userdata['session_logged_in'] )
remove
&& $userdata['session_logged_in']
the guests will be able to edit the guest posts