Oops – be careful

I mentioned the whos.amung.us badge in my Blog Toys article a week and a half ago. I think it is a fun little diversion, but just noticed something that other WordPress bloggers might want to keep in mind…

When writing a Post with WordPress, if you click “Save & Continue”, your post gets a preview at the bottom of the page. While checking the preview, I noticed the amung.us button — which is when I got a little surprise. The URL for post I was previewing showed up!

Anyone else clicking the badge around that time would get a sneak peek. For instance, while writing this post, I saw this URL in the whos.amung.us list:

http://www.solo-technology.com/blog/?p=1119&preview=true

Anyone else who had clicked the badge could follow the link.

Massive security issue? Probably not. Do I really care if anyone gets a sneak peak? Nope. But suppose the blogger is crafting a post that will be password protected before saved — but isn’t yet? That post is going to be visible!

Just something to keep in mind.

Possibly Related posts:

  1. Blog Toys
  2. Oops – Apache gets me again
  3. WordPress 2.2.3 Release – Security
  4. Oops!
  5. An Annoying Little WordPress bug


2 comments to Oops – be careful

Leave a Reply

 

 

 

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>