0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-11 02:59:07 +08:00
discourse/plugins/discourse-presence/spec/integration
discoursebot 7d4da48b47
SECURITY: Authorization bypass in wiki edit presence leaks editor identities [backport 2026.1] (#41482)
Backport of #41474 to release/2026.1.

---

## Summary

Correctly restrict wiki edit presence information to authorized users by
intersecting global edit permissions with topic-level security groups.
This prevents users outside of a private category from observing editor
identities via the presence API.

## Source

- Patch Triage: https://patch.discourse.org/patch-triage/1402

Co-authored-by: discourse-patch-triage
<272280883+discourse-patch-triage[bot]@users.noreply.github.com>

Co-authored-by: Isaac Janzen <50783505+janzenisaac@users.noreply.github.com>
2026-07-06 14:06:51 -05:00
..
presence_spec.rb SECURITY: Authorization bypass in wiki edit presence leaks editor identities [backport 2026.1] (#41482) 2026-07-06 14:06:51 -05:00