mirror of
https://github.com/discourse/discourse.git
synced 2026-08-06 06:24:48 +08:00
Backport of #40891 to release/2026.1. --- ## Summary Correctly enforce profile visibility restrictions in the subscriptions contributors endpoint and user serializers. This prevents the exposure of sensitive profile fields—including bio, location, and website—to anonymous viewers when public profiles are disabled via site settings. The fix also hardens the user and user card serializers to omit profile details for unauthorized scopes as a defense-in-depth measure. ## Source - Patch Triage: https://patch.discourse.org/patch-triage/1286 Co-authored-by: discourse-patch-triage <272280883+discourse-patch-triage[bot]@users.noreply.github.com> Co-authored-by: Isaac Janzen <50783505+janzenisaac@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| app | ||
| assets | ||
| config | ||
| db/migrate | ||
| lib | ||
| spec | ||
| test/javascripts | ||
| package.json | ||
| plugin.rb | ||
| README.md | ||
| tsconfig.json | ||
Discourse Subscriptions Plugin
Discourse Subscriptions allows site owners to sell recurring and one-time purchase subscriptions that grant access to a group on a Discourse instance.
For more information, please see: https://meta.discourse.org/t/discourse-subscriptions-plugin/140818