Communities

Writing
Writing
Codidact Meta
Codidact Meta
The Great Outdoors
The Great Outdoors
Photography & Video
Photography & Video
Scientific Speculation
Scientific Speculation
Cooking
Cooking
Electrical Engineering
Electrical Engineering
Judaism
Judaism
Languages & Linguistics
Languages & Linguistics
Software Development
Software Development
Mathematics
Mathematics
Christianity
Christianity
Code Golf
Code Golf
Music
Music
Physics
Physics
Linux Systems
Linux Systems
Power Users
Power Users
Tabletop RPGs
Tabletop RPGs
Community Proposals
Community Proposals
tag:snake search within a tag
answers:0 unanswered questions
user:xxxx search by author id
score:0.5 posts with 0.5+ score
"snake oil" exact phrase
votes:4 posts with 4+ votes
created:<1w created < 1 week ago
post_type:xxxx type of post
Search help
Notifications
Mark all as read See all your notifications »
Q&A

Welcome to Codidact Meta!

Codidact Meta is the meta-discussion site for the Codidact community network and the Codidact software. Whether you have bug reports or feature requests, support questions or rule discussions that touch the whole network – this is the site for you.

Post History

60%
+1 −0
Q&A Link to moderator help pages is presented to non-moderators

This feels like it should be a simple matter of an ability check, like we do in many other places when deciding what to show to a specific user. However, this particular link is coming from an abi...

posted 16d ago by Monica Cellio‭

Answer
#1: Initial revision by user avatar Monica Cellio‭ · 2025-02-24T18:10:25Z (16 days ago)
This feels like it *should* be a simple matter of an ability check, like we do in many other places when deciding what to show to a specific user.  However, this particular link is coming from an ability description that is seeded in the database itself -- our code simply renders the HTML it's given, and that HTML is *just* HTML, not context-aware code.

We could try to do something fancier to intercept the link, but that would mean writing some specific, fragile code that might fail for some other deployment if that seeded text were to change in the future.  All things considered, an HTTP error when trying to access content the text labeled as restricted does not seem terrible, even if in an ideal world we would have caught it.

I'm going to tag this `status-declined` but it's more `status-live-with-it-unfortunately`.