"Edit Topic" gives write-only access to other group's forums

Started by LociOiling

LociOiling Lv 1

The "Edit Topic" link on a forum post lets you move a post to a different forum.

There's a "messageboard" dropdown, which displays a long random list of all forums, which includes the forums for every group ever created in Foldit. (Subject of another report.)

If you pick a different group's forum, the post is moved to that forum. You'll then see a page stating you're not authorized to access that forum. When you'll return to the original forum, you'll find the post is in fact gone.

The messageboard dropdown shouldn't show all groups and forums, only those which the user can access.

Moving a post should also involve an access check before the post gets moved.

Just a note, there are also some mystery forums, such as "Recipe Comments", that appear in the messageboard dropdown, but don't seem to be associated with a group.