mirror of
https://gh.wpcy.net/https://github.com/discourse/discourse.git
synced 2026-06-19 05:59:26 +08:00
## Summary This is a minor security issue, DiscourseRewind::Action::BestTopics filters deleted/private/read-restricted topics, but doesn't filter by `visible=true`. ## Source - Patch Triage: https://patch.discourse.org/patch-triage/1174 - HackerOne report: https://hackerone.com/reports/3748532 --- 🤖 Auto-generated from the patch diff via Patch Triage. Review carefully before merging. Co-authored-by: discourse-patch-triage <272280883+discourse-patch-triage[bot]@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| activity_calendar.rb | ||
| ai_usage.rb | ||
| assignments.rb | ||
| base_report.rb | ||
| best_posts.rb | ||
| best_topics.rb | ||
| chat_usage.rb | ||
| favorite_gifs.rb | ||
| fbff.rb | ||
| invites.rb | ||
| most_viewed_categories.rb | ||
| most_viewed_tags.rb | ||
| new_user_interactions.rb | ||
| reactions.rb | ||
| reading_time.rb | ||
| time_of_day_activity.rb | ||
| top_words.rb | ||
| writing_analysis.rb | ||