On Sat, Nov 15, 2025, 17:36 Jelte Fennema-Nio wrote:
> On Sat, Nov 15, 2025, 07:05 Magnus Hagander wrote:
>
>> Yes, IIRC we had security complaints about people being able to enumerate
>> all users without being logged in. Since it's not just users who submitted
>> any data, it was enough to jus
On Sat, Nov 15, 2025, 07:05 Magnus Hagander wrote:
> Yes, IIRC we had security complaints about people being able to enumerate
> all users without being logged in. Since it's not just users who submitted
> any data, it was enough to just having clicked a link once...
>
I think the "without being
On Wed, Nov 12, 2025, 22:48 Jacob Champion
wrote:
> On Tue, Nov 11, 2025 at 2:12 AM Jelte Fennema-Nio wrote:
> > 3. Make user dropdowns searchable when not logged in
>
> Adding Magnus -- Magnus, do you remember the rationale for re-adding
> this protection back in 6ff8c6a52? Does it still apply?
On Tue, Nov 11, 2025 at 2:12 AM Jelte Fennema-Nio wrote:
> 3. Make user dropdowns searchable when not logged in
Adding Magnus -- Magnus, do you remember the rationale for re-adding
this protection back in 6ff8c6a52? Does it still apply?
--Jacob