Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security bug: User is able to see language statistics even no role is granted #5673

Closed
tibormarchynzoom opened this issue Mar 16, 2021 · 6 comments
Labels
question This is more a question for the support than an issue. wontfix Nobody will work on this.

Comments

@tibormarchynzoom
Copy link

Describe the issue

When you have user which does not belong to any group, any role and does not have any permission, he is still able to navigate to Languages -> Browse all languages and see all currently used languages on Weblate server.

I already tried

N/A

To Reproduce the issue

  1. Create any user
  2. Ensure that user does not belong to any group, any role or any project (even not Viewers or Users)
  3. Navigate to Languages -> Browse all languages
  4. languages are listed

Expected behavior

Languages must not be listed

Screenshots

weblate_user_without_permissions

Exception traceback

N/A

Server configuration and status

Weblate 4.5.1

Weblate deploy checks

N/A

Additional context

N/A

@nijel
Copy link
Member

nijel commented Mar 16, 2021

This is documented behaviour:

image

@nijel nijel added the question This is more a question for the support than an issue. label Mar 16, 2021
@github-actions
Copy link

This issue looks more like a support question than an issue. We strive to answer these reasonably fast, but purchasing the support subscription is not only more responsible and faster for your business but also makes Weblate stronger. In case your question is already answered, making a donation is the right way to say thank you!

@tibormarchynzoom
Copy link
Author

thanks, but don't you think it's wrong to show those data? especially if you really want to keep your environment secure.

@nijel
Copy link
Member

nijel commented Mar 16, 2021

If you don't want users to have access to any data in Weblate, don't let them register. Registered users will always be able to get some information from the service. The current scope is merely caused by implementation, and is documented.

@comradekingu
Copy link
Contributor

@tibormarchynzoom How do you think it is wrong to show that data?
In my view it is a great feature, not a "security bug"…

@github-actions
Copy link

This issue has been automatically marked as stale because there wasn’t any recent activity.

It will be closed soon if no further action occurs.

Thank you for your contributions!

@github-actions github-actions bot added the wontfix Nobody will work on this. label Mar 29, 2021
@github-actions github-actions bot closed this as completed Apr 2, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question This is more a question for the support than an issue. wontfix Nobody will work on this.
Projects
None yet
Development

No branches or pull requests

3 participants