Found the following bugs so far for Album 1.4.4 embedded in phpBB 2.0.10:
- view_album.php: "rename album" does not work (album title is not changed). Use "properties" to change title. However, bug here also (see below)
- view_album.php: Album title can be changed in "properties". However, users can enter any chars (i.e. they can enter special chars like "/" as they are not checked for).
- when phpBB2 logs out user after session has been idle, Gallery still allows new albums to be created, etc. Note new Albums, etc are created as ANONYMOUS even if this is disabled thru config (OUCH!)
- Related to the bug above: Log in as "admin", Navigate to embedded Gallery. Let phpBB2 session time out. Navigate to a phpBB2 page (non-Gallery) and log in as "userxyz". Navigate over to Gallery. It thinks you are still "admin" and gives you FULL admin permissions (OUCH!), even though you are logged in as "userxyz".
Posts: 2322
1. Rename album is not the album title, it's the album's on-disk name.
2. "Album title" is not the on disk filename, it's a descriptive name only. There doesn't need to be any character filtering.
3 & 4. We'll investigate.
Posts: 13
looks like i'll be holding off until this is sorted.
Posts: 13
is there any word on 3 & 4? need a hand with anything?
I can only do so much, bu they.. i'm willing to see these issues ironed out