mirror of
https://github.com/discourse/discourse.git
synced 2026-08-06 13:08:40 +08:00
Backport of #41962 to release/2026.1. --- ## Summary Prevent unauthorized access to raw emails by ensuring the mod has permission to view the underlying post before granting access to its raw email data. This addresses an issue where members of privileged groups could bypass visibility restrictions to view raw email content for private messages or deleted posts. Co-authored-by: discourse-patch-triage <272280883+discourse-patch-triage[bot]@users.noreply.github.com> Co-authored-by: Sam <sam.saffron@gmail.com> |
||
|---|---|---|
| .. | ||
| assets | ||
| controllers | ||
| helpers | ||
| jobs | ||
| mailers | ||
| models | ||
| queries/reports | ||
| serializers | ||
| services | ||
| views | ||