-
Notifications
You must be signed in to change notification settings - Fork 494
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Personal information leak when editing proposals #1884
Comments
Go For It! |
Anyone working on this? Right now, it is leaking names+email+usernames of all users registered on our OSEM installation. |
- Fixes openSUSE#1884 - Decided to remove real names as well, because the profile page calls out the username field as "how others users see you"
it doesn't seem so, all yours 😉 |
I have just one concern, the name is public. It is shown in the user profile page that can be seen by everybody. Why do we want to hide it? I would say the only thing we need to hide is the email. @differentreality what do you think? |
There are several points here, at least:
Well: people names are public in Facebook too and these days everybody agrees is not fun to let anyone to collect them ;) |
- Fixes openSUSE#1884 - Decided to remove real names as well, because the profile page calls out the username field as "how others users see you"
- Fixes openSUSE#1884 - Decided to remove real names as well, because the profile page calls out the username field as "how others users see you"
Let's close this then... |
Problem:
Proposal submitters has access to personal data of (probably?) all the OSEM registered users.
This is not acceptable and probably could be violating data privacy laws.
Verified in master branch at b971220
Expected behaviour:
3rd persons personal information should not be exposed to non-admin users.
Steps to reproduce:
Mitigation
You can do a quick fix with this patch:
At the cost of losing the feature of adding other speakers by the submitter.
The text was updated successfully, but these errors were encountered: