Public by Default — JavaScript Bug Hunt
Modelled on Facebook's June 2018 disclosure: between May 18 and May 27, 2018, a bug affecting about 14 million users set the suggested audience for their…
- Language: JavaScript
- Layer: Frontend
- Difficulty: Easy
- Concepts: Privacy, State, Rendering
- Modelled on: Facebook · 2018
- Visible tests: the feed composer keeps the last audience; featured items keep the last audience too
- Reward: 50 XP for a complete fix
Briefing
Modelled on Facebook's June 2018 disclosure: between May 18 and May 27, 2018, a bug affecting about 14 million users set the suggested audience for their new posts to Public, whatever they had chosen before. Facebook said it happened while it was building a new way to share featured items on profiles, and it asked affected users to review their posts.
This project is a reconstruction: audience.js picks the audience preselected in the post composer, and the locked picker.js renders it. A code path added for featured items suggests "public" outright, and the fallback for users with no history is "public" too.
Fix suggestAudience so the suggestion is always the user's own last choice, or the most private option.
Bug report
BUG-FB-AUDIENCE · Priority: High (privacy) · Reported by: user reports
suggestAudience(profile, context) returns the audience preselected in the composer. The result is the SAME whatever the context ("feed", "featured", "profile", …):
- profile.lastAudience if it is one of options.AUDIENCES
- otherwise (missing or unrecognised) the most private option, AUDIENCES[0] ("only_me")
"public" is suggested only to someone whose last choice was "public".
Observed: in the featured-items flow a user whose last post was friends-only gets "public" preselected.
Logs
[composer] ctx=featured user=… last=friends suggested=public
[composer] ctx=feed user=… last=(none) suggested=publicThe code as shipped
src/composer/audience.js (editable)
var AUDIENCES = require("./options").AUDIENCES;
// The audience preselected when the composer opens.
exports.suggestAudience = function (profile, context) {
if (context === "featured") return "public";
if (profile.lastAudience) return profile.lastAudience;
return "public";
};
Read-only context: src/composer/options.js, src/composer/picker.js.
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.