Repository navigation
[Feature] Option to limit which users non-admins can see (share/invite dialogs) #32251
Closed
OSSbear
started this conversation in
Feature Request
Replies: 1 comment
|
You're looking for the "public users" setting under https://my.immich.app/admin/system-settings?isOpen=server |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
I have searched the existing feature requests, both open and closed, to make sure this is not a duplicate request.
The feature
On a shared instance, every non-admin user can see all other users of
the server (name + email). The full user list shows up in every
dialog where you pick another user:
Scenario: Friends A, B and C use my instance. A wants to share an album
with B. A also sees C in the suggestions, although A should not know
that C uses this server at all. Album sharing between users should
keep working – users just shouldn't see everyone on the server.
For a small self-hosted instance shared between people who don't
necessarily know each other, this leaks personal data (names, email
addresses, the fact that someone uses the server). With every new
sharing feature (e.g. cluster groups in v3.2), another dialog exposes
the full list.
Technically, the full user list is exposed to every user via
GET /api/users (web) and via the users sync stream (mobile app,
UserSelectionPage reads all synced users from the local DB). So this
can't be solved on the client side or with a reverse proxy without
breaking sharing.
Proposal: Admin setting "Restrict user visibility". When enabled,
non-admins only see:
same cluster group)
To share with or invite someone new, a user enters the exact email
address instead of picking from a list. If the address doesn't
belong to an existing user, the dialog should not reveal that (to
avoid probing which emails are registered). Admins keep seeing all
users.
Platform
All reactions