Project

General

Custom queries



Profile

Actions

Defect #15123

closed

"Add watcher" leaks all active users

Added by Felix Schäfer over 11 years ago. Updated over 11 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Security
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Resolution:
Duplicate
Affected version:

Description

When adding watchers, all active users of the current installation are visible (on new issues from the get-go, on existing issues you might have to type a few characters to trigger the autocomplete).

All other places in Redmine exposing users go to great lengths to only show users that are "visible" to the current user. Attached is a patch that limits the proposed users in the watcher autocomplete to users that are members of projects visible to the current user.

(This patch was written on behalf of and contributed by Planio)


Files


Related issues

Related to Redmine - Defect #9500: Watchers list before and after creation issueNew2011-10-31

Actions
Related to Redmine - Feature #5159: Ability to add Non-Member watchers to the watch listClosedJean-Philippe Lang2010-03-23

Actions
Is duplicate of Redmine - Feature #11724: Prevent users from seeing other users based on their project membershipClosedJean-Philippe Lang

Actions
Has duplicate Redmine - Defect #15613: 'Add watchers' within the new issue reveals all the accountsClosed

Actions
#1

Updated by Toshi MARUYAMA over 11 years ago

  • Related to Defect #9500: Watchers list before and after creation issue added
#2

Updated by Toshi MARUYAMA over 11 years ago

  • Related to Feature #5159: Ability to add Non-Member watchers to the watch list added
#5

Updated by Mischa The Evil over 11 years ago

  • Related to Feature #11724: Prevent users from seeing other users based on their project membership added
#9

Updated by Jean-Philippe Lang over 11 years ago

  • Status changed from New to Closed
  • Resolution set to Duplicate
#10

Updated by Toshi MARUYAMA over 11 years ago

  • Related to deleted (Feature #11724: Prevent users from seeing other users based on their project membership)
#11

Updated by Toshi MARUYAMA over 11 years ago

  • Is duplicate of Feature #11724: Prevent users from seeing other users based on their project membership added
#12

Updated by Toshi MARUYAMA over 11 years ago

  • Has duplicate Defect #15613: 'Add watchers' within the new issue reveals all the accounts added
Actions

Also available in: Atom PDF