0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-07 13:19:19 +08:00
discourse/spec/requests
discoursebot da6a89a985
SECURITY: Enforce first-post visibility for topic bookmarks [backport 2026.7] (#42353)
Backport of #42321 to release/2026.7.

---

## Summary

Topic bookmark creation, listing, search, and reminder eligibility now
require the first post to be visible to the user. The fix adds an inner
join on the first post with hidden-post filtering to the list query and
delegates creation and visibility checks to `guardian.can_see_post?` on
the first post, preventing an authenticated user from bookmarking a
topic or searching its metadata after the first post is hidden.

## Source

- Patch Triage: https://patch.discourse.org/patch-triage/1530

Co-authored-by: discourse-patch-triage
<272280883+discourse-patch-triage[bot]@users.noreply.github.com>

---------

Co-authored-by: Chris Alberti <christo@discourse.org>
2026-08-05 12:53:16 -05:00
..
admin Revert "DEV: Promote dashboard_improvements upcoming change to beta" (#42088) 2026-07-28 19:17:43 +08:00
api SECURITY: Stop exposing hidden tag names through category serializers 2026-07-28 16:40:22 +02:00
examples
about_controller_spec.rb FEATURE: Localizable /about page fields via its settings page (#41123) 2026-06-26 20:41:08 +08:00
access_control_lists_controller_spec.rb FEATURE: Support users in DAccessControl and backend (#41358) 2026-07-15 09:18:06 +10:00
anonymous_actions_controller_spec.rb FEATURE: Prompt anonymous users to sign up after engagement clicks (#40256) 2026-05-26 09:30:38 +02:00
application_controller_spec.rb SECURITY: Prevent cache poisoning/XSS via color scheme cookies 2026-07-28 16:40:22 +02:00
associate_accounts_controller_spec.rb
badges_controller_spec.rb FEATURE: Add a granular API key scope to list badges (#41086) 2026-06-22 18:32:02 +02:00
bookmarks_controller_spec.rb SECURITY: Enforce first-post visibility for topic bookmarks [backport 2026.7] (#42353) 2026-08-05 12:53:16 -05:00
calendar_subscriptions_controller_spec.rb FEATURE: Add calendar subscription URLs to user preferences (#38598) 2026-03-17 10:28:20 -03:00
categories_controller_spec.rb SECURITY: Stop exposing hidden tag names through category serializers 2026-07-28 16:40:22 +02:00
clicks_controller_spec.rb SECURITY: Missing visibility check in click tracking endpoint (#41140) 2026-06-24 15:15:56 +10:00
composer_controller_spec.rb SECURITY: Respect group member visibility for counts (#41403) 2026-07-06 12:48:06 +08:00
composer_messages_controller_spec.rb SECURITY: Duplicate lookup reveals restricted topic titles through canonicalized URLs 2026-07-28 16:40:22 +02:00
crawler_hreflang_spec.rb UX: Prevent incomplete crawler localization settings (#41297) 2026-07-01 12:13:22 +08:00
default_headers_spec.rb
dev_mode_controller_spec.rb
directory_columns_controller_spec.rb
directory_items_controller_spec.rb SECURITY: Private UserField value disclosure via directory_items order sort side-channel (#41598) 2026-07-09 21:52:51 -05:00
discourse_id_controller_spec.rb
do_not_disturb_controller_spec.rb
drafts_controller_spec.rb FIX: Drafts/reviewables API returned 404 when acting on own resource (#39449) 2026-05-26 09:29:20 +02:00
edit_directory_columns_controller_spec.rb
email_controller_spec.rb
embed_controller_spec.rb SECURITY: Partition anonymous cache keys by Referer for embed routes [backport 2026.7] (#42368) 2026-08-05 12:51:05 -05:00
emojis_controller_spec.rb FEATURE: Locale-specific emoji search aliases (#39089) 2026-04-06 14:08:46 -03:00
exceptions_controller_spec.rb
export_csv_controller_spec.rb FIX: Suspicious login IPs bypass the moderator IP-visibility setting (#40154) 2026-05-22 13:22:32 +08:00
extra_locales_controller_spec.rb
finish_installation_controller_spec.rb
form_templates_controller_spec.rb SECURITY: Scope form template endpoints to accessible categories 2026-05-19 00:26:04 +01:00
forums_controller_spec.rb
gifs_controller_spec.rb FIX: move klipy gifs request to backend (#41540) 2026-07-08 17:18:42 +04:00
groups_controller_spec.rb SECURITY: Shared-draft titles and excerpts leak through group post serialization 2026-07-28 16:40:22 +02:00
hashtags_controller_spec.rb
highlightjs_controller_spec.rb
home_page_controller_spec.rb FEATURE: Allow fallback home routes for crawlers for custom homepage sites (#41234) 2026-06-29 09:57:40 -04:00
inline_onebox_controller_spec.rb SECURITY: Check topic visibility in Oneboxer even when categories match 2026-03-31 15:12:45 +01:00
invites_controller_spec.rb FIX: Allow logged-in users to redeem invites when new registrations are disabled (#42026) 2026-07-25 17:02:30 +02:00
list_controller_spec.rb PERF: Avoid HTML escaping preloaded JSON (#41978) 2026-07-24 09:25:06 +08:00
metadata_controller_spec.rb FEATURE: Accept shared files via the Web Share Target (#41030) 2026-06-18 17:35:09 -03:00
nested_topics_controller_spec.rb FEATURE: Hot algorithm for nested replies (simple) (#41742) 2026-07-20 10:56:05 -05:00
net_http_header_spec.rb
net_http_timeout_spec.rb
noscript_escape_spec.rb
notifications_controller_spec.rb
offline_controller_spec.rb
omniauth_callbacks_controller_spec.rb FEATURE: Allow HTML for OAuth error message (#41204) 2026-06-26 08:35:06 -05:00
onebox_controller_spec.rb SECURITY: prevent hidden profile data leak via user onebox 2026-03-19 15:21:28 +00:00
permalinks_controller_spec.rb
post_action_users_controller_spec.rb UX: Ignored users reactions/likes should not show up (#39672) 2026-05-11 15:32:29 -03:00
post_actions_controller_spec.rb SECURITY: fix is_warning type coercion bypass in PostActionsController 2026-03-19 15:21:28 +00:00
post_localizations_controller_spec.rb UX: Allow user to set post and topic title language when manually creating post translations in modal (#41734) 2026-07-16 10:43:39 +08:00
post_readers_controller_spec.rb SECURITY: Missing post-level authorization allows whisper metadata disclosure 2026-03-31 15:12:45 +01:00
posts_controller_spec.rb SECURITY: Block requests for hidden post revisions through historical version reconstruction [backport 2026.7] (#42270) 2026-08-03 12:27:57 -05:00
presence_controller_spec.rb
published_pages_controller_spec.rb SECURITY: Leakage of hidden tags to unauthorized users [backport 2026.7] (#42225) 2026-07-31 12:37:57 -05:00
push_notification_controller_spec.rb
qunit_controller_spec.rb DEV: Cache AssetProcessor code in development (#38036) 2026-02-25 11:24:41 +00:00
reviewable_claimed_topics_controller_spec.rb SECURITY: Require topic visibility for category group moderator actions 2026-05-19 00:26:04 +01:00
reviewable_notes_controller_spec.rb SECURITY: scope reviewable notes to user-visible reviewables 2026-02-26 12:22:54 +00:00
reviewables_controller_spec.rb SECURITY: Respect topic visibility in reviewable score serializer 2026-07-28 16:40:22 +02:00
robots_txt_controller_spec.rb
safe_mode_controller_spec.rb
search_controller_spec.rb SECURITY: Apply category tag visibility to full-text search (#41668) 2026-07-13 15:16:26 -03:00
session_controller_spec.rb UX: Improve password manager and full name handling in code login (#41746) 2026-07-15 10:43:03 -07:00
sidebar_sections_controller_spec.rb FIX: Allow manual Community sidebar links to be localized (#41898) 2026-07-22 15:57:56 +08:00
similar_topics_controller_spec.rb
site_controller_spec.rb SECURITY: Anonymous sidebar serialization exposes descriptions of category-restricted tags 2026-07-28 16:40:22 +02:00
sitemap_controller_spec.rb
slugs_controller_spec.rb
static_controller_spec.rb FIX: Localize static topic pages … (#41260) 2026-06-29 21:34:17 +08:00
steps_controller_spec.rb
stylesheets_controller_spec.rb DEV: Drop empty core mobile/desktop stylesheets (#41988) 2026-07-23 20:30:13 +01:00
svg_sprite_controller_spec.rb
tag_groups_controller_spec.rb FIX: Prevent tag group from saving if private + no group selected (#39599) 2026-04-29 12:10:45 +08:00
tag_localizations_controller_spec.rb FIX: Clean localized tag names (#38488) 2026-03-12 12:54:50 +08:00
tags_controller_spec.rb FIX: Allow selecting tags that are only used in personal messages (#41918) 2026-07-24 12:27:03 +02:00
theme_import_map_spec.rb DEV: Improve cross-plugin/theme import handling (#40939) 2026-06-30 16:11:38 +01:00
theme_javascripts_controller_spec.rb PERF: Move theme settings from js bundle to preload data (#40137) 2026-06-08 16:04:56 +01:00
topic_localizations_controller_spec.rb UX: Allow user to set post and topic title language when manually creating post translations in modal (#41734) 2026-07-16 10:43:39 +08:00
topic_view_stats_controller_spec.rb
topics_controller_spec.rb FIX: Scope duplicate topic title check to what the user can see (#41871) 2026-07-24 15:35:35 +02:00
uploads_controller_multisite_spec.rb
uploads_controller_spec.rb FIX: Serve inline-safe uploads inline on the local file store (#40739) 2026-07-14 18:52:35 +01:00
user_actions_controller_spec.rb FEATURE: Change default upcoming change promotion status to Beta (#41275) 2026-07-06 09:13:37 +10:00
user_api_key_clients_controller_spec.rb
user_api_keys_controller_spec.rb Revert "FIX: Only allow OTPs to be generated from a browser session (#40964)" (#41875) 2026-07-22 18:18:02 +03:00
user_avatars_controller_spec.rb SECURITY: Improve SVG sanitization 2026-06-30 16:10:52 +02:00
user_badges_controller_spec.rb SECURITY: Prevent badge lookup from exposing hidden profiles (#41160) 2026-06-25 13:01:03 +08:00
user_status_controller_spec.rb FIX: Post serialization exposes hidden-profile user status messages (#40885) 2026-06-15 09:25:47 -05:00
users_controller_spec.rb SECURITY: Enforce first-post visibility for topic bookmarks [backport 2026.7] (#42353) 2026-08-05 12:53:16 -05:00
users_email_controller_spec.rb DEV: CSRF Token Not Invalidated After Password Reset (#40998) 2026-06-17 16:07:30 -04:00
webhooks_controller_spec.rb SECURITY: Prevent any signed AWS SNS TopicARN from being accepted via webhooks 2026-06-30 16:10:52 +02:00
wizard_controller_spec.rb