Skip to content

Commit 7efa41b

Browse files
committedMar 13, 2023
Merge branch '1820151'
* 1820151: Bug 1820151 - Mozilla Phabricator emails allow any user to secretly access secure revision title, comments and private files
2 parents f976435 + c8abff8 commit 7efa41b

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed
 

‎moz-extensions/src/email/resolve/ResolveComments.php

+2-2
Original file line numberDiff line numberDiff line change
@@ -180,9 +180,9 @@ private static function renderCommentMarkup($markup): EmailCommentMessage
180180

181181
private static function createMarkupEngine($mode) {
182182
return PhabricatorMarkupEngine::newMarkupEngine(array())
183-
->setConfig('viewer', PhabricatorUser::getOmnipotentUser())
183+
->setConfig('viewer', new PhabricatorUser())
184184
->setConfig('uri.base', PhabricatorEnv::getProductionURI('/'))
185185
->setConfig('uri.full', true)
186186
->setMode($mode);
187187
}
188-
}
188+
}

0 commit comments

Comments
 (0)
Failed to load comments.