0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-08 17:53:55 +08:00
discourse/plugins/discourse-subscriptions/spec/requests
discoursebot c774474881
SECURITY: Subscription contributors expose full user profile fields to anonymous viewers [backport 2026.1] (#40894)
Backport of #40891 to release/2026.1.

---

## Summary

Correctly enforce profile visibility restrictions in the subscriptions
contributors endpoint and user serializers. This prevents the exposure
of sensitive profile fields—including bio, location, and website—to
anonymous viewers when public profiles are disabled via site settings.
The fix also hardens the user and user card serializers to omit profile
details for unauthorized scopes as a defense-in-depth measure.

## Source

- Patch Triage: https://patch.discourse.org/patch-triage/1286

Co-authored-by: discourse-patch-triage
<272280883+discourse-patch-triage[bot]@users.noreply.github.com>

Co-authored-by: Isaac Janzen <50783505+janzenisaac@users.noreply.github.com>
2026-06-15 10:24:34 -05:00
..
admin SECURITY: Fixes for discourse-subscriptions [backport 2026.1] 2026-03-31 15:12:50 +01:00
user SECURITY: Fixes for discourse-subscriptions [backport 2026.1] 2026-03-31 15:12:50 +01:00
admin_controller_spec.rb
hooks_controller_spec.rb FIX: Gate checkout provisioning on payment_status and handle async payments [backport 2026.1] 2026-05-19 00:26:55 +01:00
subscribe_controller_spec.rb SECURITY: Subscription contributors expose full user profile fields to anonymous viewers [backport 2026.1] (#40894) 2026-06-15 10:24:34 -05:00