-
Notifications
You must be signed in to change notification settings - Fork 198
Possible security issue with user name-contact page #1106
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Quick fix: add |
I don't think that we ever considered names and emails to require security -- the users are primarily package uploaders, and their contact information is expected to be public. |
@gbaz that's plain wrong On https://hackage.haskell.org/users/register-request it's very clearly stated that
My account management email may well be different from "send all spam here" email. (or I might use |
Oh fair 'nuff. In that case a pr changing this is welcome. |
Page
https://hackage.haskell.org/user/:username/name-contact
can be visited without authorization where:username
can be any username, and user's full name and email can be viewed on that page. This seems to be a security issue.The text was updated successfully, but these errors were encountered: