Project

General

Profile

Actions

Defect #15123

closed

"Add watcher" leaks all active users

Added by Felix Schäfer over 12 years ago. Updated over 12 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Security
Target version:
-
Resolution:
Duplicate
Affected version:

Description

When adding watchers, all active users of the current installation are visible (on new issues from the get-go, on existing issues you might have to type a few characters to trigger the autocomplete).

All other places in Redmine exposing users go to great lengths to only show users that are "visible" to the current user. Attached is a patch that limits the proposed users in the watcher autocomplete to users that are members of projects visible to the current user.

(This patch was written on behalf of and contributed by Planio)


Files


Related issues

Related to Redmine - Defect #9500: Watchers list before and after creation issueNew2011-10-31Actions
Related to Redmine - Feature #5159: Ability to add Non-Member watchers to the watch listClosedJean-Philippe Lang2010-03-23Actions
Is duplicate of Redmine - Feature #11724: Prevent users from seeing other users based on their project membershipClosedJean-Philippe LangActions
Has duplicate Redmine - Defect #15613: 'Add watchers' within the new issue reveals all the accountsClosedActions
Actions

Also available in: Atom PDF