Creator Hub allows you to see the 'Overview' page of any game, regardless of whether you have access

After the recent update to the Creator Hub website layout, I’ve found that you can now visit the ‘Overview’ page of any experience, even if you do not developer access to said experience. The page fully loading implies that you have analytics access (hence are likely a developer of the game), and shouldn’t be shown at all if you’re not. Before the layout changes, visiting the affected URL would display a forbidden page which is the intended behavior.

Reproduction Steps (using Work at a Pizza Place as an example):

  1. Log in to the Roblox Creator Hub.
  2. Go to this URL.
  3. An ‘Overview’ page will be displayed that visually implies you have developer access when, in reality, you do not.

Affected URL (with an example universe ID): https://create.roblox.com/dashboard/creations/experiences/47545/overview

Expected Behavior:
When visiting the overview page of an experience without proper access, the website should display a ‘Forbidden’ page or a clear message indicating that you do not have the necessary permissions to view the page.

Page URL: https://create.roblox.com/dashboard/creations/experiences/universe-id-that-you-do-not-have-access-to/overview

1 Like

To make it clear, this wasn’t always the case. In the past, the exact same issue would occur allowing you to view the overview (/ basic settings?) page of any experience in the creator dashboard and it wasn’t too long ago that this was possible either.

2 Likes

Thanks for the correction. Either way, would still be great if this was resolved.

2 Likes

Hey,

Thanks for the report - I’ve flagged with the team. It would appear that this is a visual bug only; we’re not actually releasing any private information (such as analytics access) to people who shouldn’t be able to see it. Let me know if that’s not the case!

Thanks

:wave: Thanks for the response. You’re correct, just a visual bug - no issues with private information being exposed.

Do keep me updated on this. :slightly_smiling_face:

1 Like

@Burgundy2014 Going to mention you here as you’ve responded to a similar report, and it seems this has been forgotten about.

This issue should be resolved now. Thanks for reporting!

2 Likes

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.