mirror of
https://gh.wpcy.net/https://github.com/discourse/discourse.git
synced 2026-06-19 01:44:11 +08:00
## Summary This is a minor security issue, DiscourseRewind::Action::BestTopics filters deleted/private/read-restricted topics, but doesn't filter by `visible=true`. ## Source - Patch Triage: https://patch.discourse.org/patch-triage/1174 - HackerOne report: https://hackerone.com/reports/3748532 --- 🤖 Auto-generated from the patch diff via Patch Triage. Review carefully before merging. Co-authored-by: discourse-patch-triage <272280883+discourse-patch-triage[bot]@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| controllers/discourse_rewind | ||
| services/discourse_rewind | ||
| .gitkeep | ||