Clicking a user on a site with Remarkbox installed shows all that user's Remarkbox comments everywhere [solved]

devilgate 5y, 277d ago [edited]

If I click on a user who has left a Remarkbox comment on my own site, I see all their comments from Remarkbox. That is, all the comments they have made using Remarkbox anywhere (I assume).

So if for example you go to my post here and click on Russell's username, you'll see all his comments on Remarkbox, but shown as if they belong on my site.

Seeing all the comments a user has made on my site would be reasonable, if probably not what people would expect. But the the current situation seems like a privacy problem, as well as potentially being very confusing.


Comments

hide preview ▲show preview ▼

What's next? verify your email address for reply notifications!

timehexon 3d, 5h ago [edited]

This has been fixed. When you click a username now, you'll only see their comments from the site you're currently on -- not from every other site using Remarkbox. The profile page also respects the namespace's moderation settings, so if a namespace hides unverified or unapproved comments, those won't show up on profiles either.

The root cause was that the user profile query had no namespace filter -- it just pulled every comment a user had ever made, everywhere. That's been scoped down.

Full details: https://git.unturf.com/engineering/remarkbox/remarkbox/-/blob/main/docs/tickets/0.md

remark link
hide preview ▲show preview ▼

What's next? verify your email address for reply notifications!

devilgate 2d, 16h ago

Not bad, only 5 years, 274 days! :)

remark link parent
hide preview ▲show preview ▼

What's next? verify your email address for reply notifications!

russell 1d, 19h ago [edited]

Claude Code addressed most of the back log yesterday. lol his name is timehexon's hexagonal familiar spirit.

https://www.timehexon.com

hide preview ▲show preview ▼

What's next? verify your email address for reply notifications!

Xii 4y, 363d ago

Even worse, it displays comments that are waiting for approval!

remark link
hide preview ▲show preview ▼

What's next? verify your email address for reply notifications!

russell 4y, 363d ago [edited]

Confirmed. We should address this too. I'll take a look at it shortly.

Update: this was fixed in production.

hide preview ▲show preview ▼

What's next? verify your email address for reply notifications!

Xii 4y, 364d ago

Agreed. It could be a big problem when one site allows conversation that another one wouldn't. Imagine seeing comments from a porn site on a church's site, for example.

remark link
hide preview ▲show preview ▼

What's next? verify your email address for reply notifications!

russell 4y, 364d ago

Hmmm. Good call out. We should address this.

hide preview ▲show preview ▼

What's next? verify your email address for reply notifications!