Announcement

#1 2020-04-10 21:39:42

SilverHawk
Member
2020-04-10
3

Security Issue with Calendar View?

Hello,

New Piwigo user here but I'm a retired software developer, so not a complete newbie...

I have about 3500 photos in 15 albums and all albums are private.  When I go to my piwigo site before logging in, I see title, page headers etc but no photos or albums(as expected).  When I log in, everything is fine and I see everything.

But today, I happen to press the "display a calendar by creation date" icon in the top right BEFORE logging in, and I got the following deprecated PHP error followed by a display of all 30 photos from the last calendar action I did when logged in.

"Deprecated: implode(): Passing glue string after array is deprecated. Swap the parameters in /home/elecscou/public_html/piwigo/include/dblayer/functions_mysqli.inc.php on line 688"


To make sure it was not a browser or client cache related problem,  I repeated the test in Microsoft Edge on another desktop PC which is not a browser I used.

I hope this is a quick and easy fix.  It has dented my faith a little in Piwigo as a secure place to store & display my family photos. Apart from this, I love it!


Piwigo version: 2.10.2
PHP version: 7.4.4
MySQL version: 10.2.31-MariaDB-log-cll-lve
Piwigo URL: http://12cats.co.uk

Offline

 

#2 2020-04-10 21:53:47

erAck
Only trying to help
2015-09-06
2026

Re: Security Issue with Calendar View?

It's not an error, it's just a deprecated message. Search the forum for deprecated, there are dozens of places that mention Piwigo's php error setting to suppress those messages.


Running Piwigo at https://erack.net/gallery/

Offline

 

#3 2020-04-10 22:02:53

SilverHawk
Member
2020-04-10
3

Re: Security Issue with Calendar View?

erAck wrote:

It's not an error, it's just a deprecated message. Search the forum for deprecated, there are dozens of places that mention Piwigo's php error setting to suppress those messages.

Thanks for speedy reply, and point taken about the deprecated message, but what about the photos that should not be accessible / viewable until a successful log in?

Offline

 

#4 2020-04-10 23:24:38

erAck
Only trying to help
2015-09-06
2026

Re: Security Issue with Calendar View?

I don't know and don't know what you did to make the photos not accessible. Did you assign/associate/link them to a private album? Or did you just "hide" the album(s) from the main page? In that case the images are retrievable by other searches. Fwiw, the same images are shown under Recent photos and Random photos, so I assume they are not (only) linked to a private album.


Running Piwigo at https://erack.net/gallery/

Offline

 

#5 2020-04-11 00:12:22

SilverHawk
Member
2020-04-10
3

Re: Security Issue with Calendar View?

Thanks for your help.  My fault although I'm still not sure exactly what I did.

I was using the OpenStreetMap plugin and zoomed down to a location with 30 photos and then pressed "Show All".  That created an OSM virtual album with public access.  I didn't realise that 1) these OSM virtual albums hang around and 2) they were public.

I guess I need to go and read up more on the use of this plugin :(

Offline

 

Board footer

Powered by FluxBB

github twitter newsletter Donate Piwigo.org © 2002-2024 · Contact