After upgrading to J! 2.5 (and updating boutique template) Our K2 item access policies (and even unpublished state) no longer appears to be respected. Marking an item "special" causes the template to display the "you are not authorized..." notice but the page is still displayed for anyone with the URL. Unpublishing the item causes the template to display "item not found" but the page is still rendered.
Both options cause both notices but in all cases the page still shows up. This is a big security hole on our site at the moment.
This category is on special access but with the direct URL you can see the page, not the listings:
http://www.design3.com/industry-insight ... oductions/
However a direct URL to the item will display it:
http://www.design3.com/industry-insight ... l-lebreton
How can we fix this quickly?
Thanks,
Case