Feature #3720

account/show/:user_id should not be accessible for other users not in your projects

Added by Lucas Panjer over 8 years ago. Updated about 8 years ago.

Status:ClosedStart date:2009-08-07
Priority:NormalDue date:
Assignee:-% Done:

0%

Category:Accounts / authentication
Target version:0.8.6
Resolution:Fixed

Description

We use Redmine in a setting where certain users should not be able to see the name and email of every other user in the system. For example, when you have two separate clients involved in separate private projects, these clients shouldn't be able to access each others user profile at /account/show/:other_user_id. They should have no way of discovering other users in the same system that aren't involved in their projects.

To increase privacy and security of a Redmine system, particularily where it is not good to expose who all the users are it would be nice to restrict access to those users which are in public projects or private projects that the current user is also in.


Related issues

Related to Redmine - Defect #4129: Anonymous users can get all user's information Closed 2009-10-28
Duplicated by Redmine - Defect #5351: View /account/show/id-user on Redmine 0.9.2 Closed 2010-04-19 2010-04-21

Associated revisions

Revision 2986
Added by Jean-Philippe Lang about 8 years ago

Do not show user profile if no visible project or activity (#4129, #3720).

History

#1 Updated by Jean-Philippe Lang about 8 years ago

  • Tracker changed from Defect to Feature

#2 Updated by Jean-Philippe Lang about 8 years ago

  • Category set to Accounts / authentication
  • Status changed from New to Closed
  • Target version set to 0.8.6
  • Resolution set to Fixed

Fixed in r2986. User won't be displayed if there's no visible project or activity.

#3 Updated by Jean-Philippe Lang about 8 years ago

  • Target version changed from 0.8.6 to 0.9.0

#4 Updated by Jean-Philippe Lang about 8 years ago

  • Target version changed from 0.9.0 to 0.8.6

Merged in 0.8 branch in r2987.

Also available in: Atom PDF