+assignedbugs page shows hidden memberships

Bug #253970 reported by Andrea Corbellini
260
Affects Status Importance Assigned to Milestone
Launchpad itself
Fix Released
Critical
Edwin Grubbs

Bug Description

Look at <https://bugs.launchpad.net/~matthew.revell/+assignedbugs>. Under "Matthew Revell's teams" there's ~canonical which is a "hidden" team whereof the members shouldn't be shown, as told in <https://launchpad.net/~canonical> ("You are not allowed to view this team's membership").

Tags: lp-bugs
Revision history for this message
Steve Alexander (stevea) wrote :

I have confirmed that the +assignedbugs page is leaking that a user is in a private team, even when I'm accessing Launchpad as an anonymous user.

Changed in malone:
importance: Undecided → Critical
status: New → Triaged
Changed in malone:
assignee: nobody → edwin-grubbs
Changed in malone:
status: Triaged → In Progress
Revision history for this message
Edwin Grubbs (edwin-grubbs) wrote :

Fixed in r6789. Cherry-picked to edge and lpnet.

Changed in malone:
status: In Progress → Fix Released
milestone: none → 2.1.8
Revision history for this message
Christian Reis (kiko) wrote :

Verified fixed on edge and lpnet.

Curtis Hovey (sinzui)
visibility: private → public
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.