We are currently developing a site where we have users that can log in and create content which only they can control (read/write). However, we found that if they create some content (oursite.com/someuser/personalcontent), anyone can paste in this URL and read their content without having to log in first as the creator of the content. How do we fix this security hole?






