User without Participate Everywhere can comment freely #1538
Labels
area: backend
Changes to server-side code
complexity: unassessed
Needs further developer investigation before complexity/feasibility can be determined.
priority: high
type: bug
Something isn't working
The Participate ability allows you to comment on your own posts and answers to your own questions, but not more broadly (according to the documentation). Participate Everywhere allows commenting everywhere. However, this restriction isn't working -- a newly-created user with only Participate was able to comment on an existing comment thread, and I just tested in a dev environment and found that such a user can also create new comment threads on other users' posts. It seems we are not enforcing this restriction, and spammers are able to exploit it. (I found out it wasn't working because of a spam flag.)
The text was updated successfully, but these errors were encountered: