Actions
Defect #42100
closedIf new user is not attached to any project, he can see all users via URL simply typing numbers https://redmine.org/users/50
Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Permissions and roles
Target version:
-
Start date:
Due date:
% Done:
0%
Estimated time:
Resolution:
Duplicate
Affected version:
Description
If new user is not attached to any project, he can see all users via URL simply typing numbers after /users/{number}
for example: https://redmine.org/users/50
In order to prevent this, user must be attached to some project with some role, otherwise, he can see list of all users.
Related issues
Actions