0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-06 13:08:40 +08:00
discourse/plugins
Chris Alberti 6e5418453b
SECURITY: Remove stale invitee access for users removed from invited groups on private events [backport 2026.1] (#42229)
Backport of #42187 to release/2026.1.

Manual backport required since livestream wasn't yet moved into
discourse-calendar at this time so related changes were removed, and a
couple other fixes were (cleanly) cherry-picked to support the backport:
- #37662 and #37663 
   InviteesController bug fixes
- #38023 
Moves InivteesController logic into Services and adds additional
security checks as policies
- #40487 
Stops memoizing can_act_on_discourse_post_event? so we don't fall back
to a cached value

---

## Summary

Correctly restrict private calendar event access to current group
members. The patch replaces stale invitee-row authorization with active
invited-group membership checks across event detail serialization,
attendance searches, RSVP mutations, and livestream chat metadata, and
prunes stale invitee records when a user is removed from a group.

## Source

- Patch Triage: https://patch.discourse.org/patch-triage/1377

Co-authored-by: discourse-patch-triage
<272280883+discourse-patch-triage[bot]@users.noreply.github.com>

---------

Co-authored-by: Joffrey JAFFEUX <j.jaffeux@gmail.com>
Co-authored-by: Renato Atilio <renato@discourse.org>
2026-08-03 10:37:47 -05:00
..
automation FIX: Prevent automation set_topic_timer from reopening closed topics [backport 2026.1] (#42174) 2026-07-30 09:19:16 -05:00
chat SECURITY: Private Chat Threat Message Disclosure via Chat Onebox Channel/Threat ID Mismatch [backport 2026.1] 2026-07-28 17:00:54 +02:00
checklist DEV: upgrade to fontawesome 7 (#36286) 2026-01-14 12:58:36 +01:00
discourse-adplugin I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
discourse-affiliate I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
discourse-ai SECURITY: Scope AI bot reply stream to the PM's participants [backport 2026.1] 2026-07-28 17:00:54 +02:00
discourse-apple-auth I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
discourse-assign SECURITY: Honor group visibility in discourse-assign group lookups [backport 2026.1] (#41198) 2026-06-25 13:58:03 -03:00
discourse-cakeday I18N: Update translations (#37056) 2026-01-12 15:18:57 +01:00
discourse-calendar SECURITY: Remove stale invitee access for users removed from invited groups on private events [backport 2026.1] (#42229) 2026-08-03 10:37:47 -05:00
discourse-chat-integration I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
discourse-data-explorer SECURITY: Strip SQL comments and use non-recursive parameter interpolation in Data Explorer [backport 2026.1] 2026-07-31 22:01:42 +01:00
discourse-details I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
discourse-gamification FIX: add guard to prevent jobs from running (#42140) (#42144) 2026-07-29 17:53:00 -03:00
discourse-github I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
discourse-graphviz SECURITY: Prevent Sidekiq DoS via Graphviz rendering [backport 2026.1] (#40752) 2026-06-10 18:13:50 +01:00
discourse-hcaptcha I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
discourse-lazy-videos UX: add admin sidebar icons for preinstalled plugins (#36764) 2025-12-18 16:39:00 -05:00
discourse-local-dates SECURITY: Prevent HTML injection in discourse-local-dates rendering [backport 2026.1] 2026-07-28 17:00:54 +02:00
discourse-login-with-amazon I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
discourse-lti I18N: Update translations (#37101) 2026-01-14 09:39:58 +01:00
discourse-math I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
discourse-microsoft-auth I18N: Update translations (#37056) 2026-01-12 15:18:57 +01:00
discourse-narrative-bot I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
discourse-oauth2-basic I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
discourse-openid-connect I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
discourse-patreon SECURITY: authentication bypass vulnerability 2026-02-26 12:24:37 +00:00
discourse-policy SECURITY: Validate policy permissions on post save 2026-03-19 15:46:24 +00:00
discourse-post-voting SECURITY: Reviewable conversations expose post-voting flag PM excerpts to category moderators outside the PM [backport 2026.1] (#41531) 2026-07-07 15:37:32 -05:00
discourse-presence SECURITY: Authorization bypass in wiki edit presence leaks editor identities [backport 2026.1] (#41482) 2026-07-06 14:06:51 -05:00
discourse-reactions SECURITY: anonymous users can read hidden real names via reaction-user endpoints [backport 2026.1] (#41935) 2026-07-22 14:11:22 -05:00
discourse-rewind I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
discourse-rss-polling I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
discourse-solved SECURITY: Hidden first-post excerpt is emitted in Q&A schema JSON-LD [backport 2026.1] 2026-07-28 17:00:54 +02:00
discourse-subscriptions SECURITY: Subscription contributors expose full user profile fields to anonymous viewers [backport 2026.1] (#40894) 2026-06-15 10:24:34 -05:00
discourse-templates SECURITY: Templates endpoint exposes hidden tag names [backport 2026.1] 2026-07-28 17:00:54 +02:00
discourse-topic-voting I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
discourse-user-notes SECURITY: Unauthorized Post Data Exposure in discourse-user-notes Plugin 2026-03-19 15:46:24 +00:00
discourse-zendesk-plugin SECURITY: Block ticket creation when user can't see the topic 2026-03-19 15:46:24 +00:00
footnote I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
poll SECURITY: Uncontrolled Resource Consumption in Number Poll Generation [backport 2026.1] (#41151) 2026-06-24 15:53:17 +10:00
spoiler-alert I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
styleguide I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00