Document Library showing all files/folders regardless of file/folder permissions

Permalink 0 0 Browser Info Environment
I have enabled advanced permissions
Added new members
In file manage create folder for each member set to view files for the relevant member.
Create set for members documents.
Upload files to members folders and add to set.
Add document block to pages and select set to display.
Publish edits.
Sign in as one of the members and all folders plus all files in set are displayed.
Click on file that you do not have view permissions for and get invalid file massage.

I was expecting the correct behavior would be to not see files or folders listed that you do not have permissions for.


Status: New
cmerritt

concrete5 Environment Information

# concrete5 Version
Core Version - 8.3.2
Version Installed - 8.3.2
Database Version - 20180122213656

# concrete5 Packages
Afixia: Login Redirect (0.9.2), List files from set (1.0.13), Login Dialog (0.9.7), Pixel Theme (2.0.3), Simple Gallery (1.0.7), User Info (1.2.2)

# concrete5 Overrides
blocks/login_dialog/templates/top_bar/view.php, blocks/login_dialog/templates/top_bar/view.css, blocks/login_dialog/templates/top_bar, blocks/login_dialog/templates, blocks/login_dialog

# concrete5 Cache Settings
Block Cache - Off
Overrides Cache - Off
Full Page Caching - Off
Full Page Cache Lifetime - Every 6 hours (default setting).

# Server Software
Apache/2.4.29 (cPanel) OpenSSL/1.0.2n mod_bwlimited/1.4

# Server API
cgi-fcgi

# PHP Version
5.6.33

# PHP Extensions
bcmath, calendar, cgi-fcgi, Core, ctype, curl, date, dom, ereg, fileinfo, filter, ftp, gd, hash, iconv, imap, ionCube Loader, json, libxml, mbstring, mcrypt, mhash, mysql, mysqli, mysqlnd, openssl, pcntl, pcre, PDO, pdo_mysql, pdo_sqlite, Phar, posix, readline, Reflection, session, SimpleXML, soap, sockets, SPL, sqlite3, standard, tokenizer, wddx, xml, xmlreader, xmlwriter, xsl, zip, zlib

# PHP Settings
max_execution_time - 600
log_errors_max_len - 1024
max_file_uploads - 20
max_input_nesting_level - 64
max_input_time - 600
max_input_vars - 1000
memory_limit - 1024M
post_max_size - 8M
sql.safe_mode - Off
upload_max_filesize - 128M
mysql.max_links - Unlimited
mysql.max_persistent - Unlimited
mysqli.max_links - Unlimited
mysqli.max_persistent - Unlimited
pcre.backtrack_limit - 1000000
pcre.recursion_limit - 100000
session.cache_limiter - <i>no value</i>
session.gc_maxlifetime - 7200
soap.wsdl_cache_limit - 5

Browser User-Agent String

Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0