Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Private messages are included on local timeline #303

Closed
koehn opened this issue Feb 16, 2023 · 15 comments
Closed

Private messages are included on local timeline #303

koehn opened this issue Feb 16, 2023 · 15 comments

Comments

@koehn
Copy link
Contributor

koehn commented Feb 16, 2023

  1. From the Mastodon client, create a Toot.
  2. Set the audience to “only people I mention” and mention someone, and send the message
  3. Go to the main https page for your site (e.g., https://example.com/explore) and select “Local” from the list on the right
  4. Your private messages are displayed there
@ThatOneCalculator

This comment was marked as spam.

@Sqaaakoi

This comment was marked as spam.

@spacekookie

This comment was marked as spam.

@ThatOneCalculator

This comment was marked as spam.

@richfelker
Copy link

Has anyone clarified whether this is only visible logged in as yourself (laughably bad ux that could be panic inducing for users, but not actually a privacy leak) or publicly?

@WesleyAC

This comment was marked as spam.

@ThatOneCalculator

This comment was marked as spam.

@WesleyAC

This comment was marked as spam.

@EvelynSubarrow

This comment was marked as spam.

@ThatOneCalculator

This comment was marked as spam.

@cloudflare cloudflare locked as spam and limited conversation to collaborators Feb 22, 2023
@xtuc
Copy link
Member

xtuc commented Feb 22, 2023

Currently private messages are not supported, they might be displayed on public timelines. I temporarly locked this issue to avoid spam.

@cloudflare cloudflare unlocked this conversation Feb 23, 2023
@EvelynSubarrow
Copy link

Would I be correct in thinking that incoming private messages (and not just outgoing private messages) would be publicly available?

@jae1911

This comment was marked as spam.

@cloudflare cloudflare locked as too heated and limited conversation to collaborators Feb 23, 2023
@xtuc
Copy link
Member

xtuc commented Feb 23, 2023

Locking the issue permanently.

As I said in #303 (comment). At the moment, private messages are not supported and we are well aware. Our team is looking into it.

Thanks for the issue @koehn. Feel free to reach out to me directly on Discord for concerns / questions.

@xtuc
Copy link
Member

xtuc commented Feb 23, 2023

A fix has been merged. Private messages sent from Wildeebest are not showing in public timelines anymore. Please sync your forks to patch your instance.

Also note that, for safety, toots with private or unlisted visbility are now rejected until we implement them properly.

In the future, issues that could be security related can be reported via https://github.com/cloudflare/wildebeest/blob/main/SECURITY.md.

Closing this since the original issue has been addressed.

@xtuc xtuc closed this as completed Feb 23, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

9 participants