2 rating bugs for the price of one
|
|
By Defect , Section Code [] Posted on Wed Jan 17, 2001 at 12:00:00 PM PST
|
|
An anonymous hero (unlogged in user or random passerby) can rate comments by appending ";rating_[comment_number];rate=Rate+All;" (that's why some people have had "Anonymous User" as someone who's rated their comments, someone found it but didn't report it apparently)
Scoop doesn't check whether or not the rater has a uid of -1, it assumes security because it doesn't show the rating drop downs when a user is not logged in.
|
Also, hidden comments are still ratable by normal users by using the same method above. I don't think this is really a big deal, but it's just something that should be known (if it wasn't already).
(though you can't see the comment, you can get the # if a trusted gives you the url, or by simple deduction) |
|
Story Views
|
16 Scoop users have viewed this story.
|
|