Skip to content
This repository was archived by the owner on Feb 15, 2026. It is now read-only.

fix(middleware): enhanced user privacy on profile pages#3695

Closed
fallenbagel wants to merge 1 commit intosct:developfrom
fallenbagel:fix-user-privacy
Closed

fix(middleware): enhanced user privacy on profile pages#3695
fallenbagel wants to merge 1 commit intosct:developfrom
fallenbagel:fix-user-privacy

Conversation

@fallenbagel
Copy link
Copy Markdown
Contributor

Description

Addresses a security vulnerability where the /users/[:id] route was accessible to users without the necessary permissions. Adds middleware that protects that route so that only authenticated users with the MANAGE_USERS and VIEW_WATCHLIST permissions can access other user's profile pages as intended.

(unless if the current behavior is the intended behavior, then feel free to close the PR 😄 ).

To-Dos

  • Successful build yarn build

Addresses a security vulnerability where the `/users/[:id]` route was accessible to users without
the necessary permissions. Adds middleware that protects that route so that only authenticated users
with the `MANAGE_USERS` and `VIEW_WATCHLIST` permissions can access other user's profile pages as
intended.
@TheCatLady
Copy link
Copy Markdown
Collaborator

The current behavior is the intended behavior. The content visible on profile pages is dependent on the active user's permissions.

@fallenbagel
Copy link
Copy Markdown
Contributor Author

fallenbagel commented Nov 19, 2023

The current behavior is the intended behavior. The content visible on profile pages is dependent on the active user's permissions.

Ah I see. This was raised because there were users who wanted the usernames/pfps and such to not be exposed to other users unless given the permission to do so as it concerns privacy

Alright will close this c:

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants