0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-06 13:08:40 +08:00
discourse/spec/requests
Bannon Tanner 2625630482
SECURITY: Stale featured rows expose unlisted topic content (#41810)
## Summary

Prevent the exposure of unlisted topic metadata in the categories
response by enforcing live visibility checks on featured topics.
Additionally, the UserSilencer service now correctly removes featured
topic records when bulk-hiding topics from new users, ensuring stale
records do not bypass visibility constraints.

## Source

- Patch Triage: https://patch.discourse.org/patch-triage/1427

Co-authored-by: discourse-patch-triage
<272280883+discourse-patch-triage[bot]@users.noreply.github.com>
2026-07-17 09:19:08 -05:00
..
admin FIX: Restore enabled checkboxes for similar users in penalty modals (#41801) 2026-07-17 17:14:39 +05:30
api FEATURE: Allow inviting new users directly as admins (#41748) 2026-07-16 14:59:24 -07:00
examples
about_controller_spec.rb FEATURE: Localizable /about page fields via its settings page (#41123) 2026-06-26 20:41:08 +08:00
access_control_lists_controller_spec.rb FEATURE: Support users in DAccessControl and backend (#41358) 2026-07-15 09:18:06 +10:00
anonymous_actions_controller_spec.rb FEATURE: Prompt anonymous users to sign up after engagement clicks (#40256) 2026-05-26 09:30:38 +02:00
application_controller_spec.rb SECURITY: Bind shared session key to auth token and enforce user gates (#41610) 2026-07-14 13:25:05 +08:00
associate_accounts_controller_spec.rb
badges_controller_spec.rb FEATURE: Add a granular API key scope to list badges (#41086) 2026-06-22 18:32:02 +02:00
bookmarks_controller_spec.rb
calendar_subscriptions_controller_spec.rb FEATURE: Add calendar subscription URLs to user preferences (#38598) 2026-03-17 10:28:20 -03:00
categories_controller_spec.rb SECURITY: Stale featured rows expose unlisted topic content (#41810) 2026-07-17 09:19:08 -05:00
clicks_controller_spec.rb SECURITY: Missing visibility check in click tracking endpoint (#41140) 2026-06-24 15:15:56 +10:00
composer_controller_spec.rb SECURITY: Respect group member visibility for counts (#41403) 2026-07-06 12:48:06 +08:00
composer_messages_controller_spec.rb SECURITY: Whisper metadata disclosure via stale TopicLinks (#41139) 2026-06-24 14:44:27 +10:00
crawler_hreflang_spec.rb UX: Prevent incomplete crawler localization settings (#41297) 2026-07-01 12:13:22 +08:00
default_headers_spec.rb
dev_mode_controller_spec.rb
directory_columns_controller_spec.rb
directory_items_controller_spec.rb SECURITY: Private UserField value disclosure via directory_items order sort side-channel (#41598) 2026-07-09 21:52:51 -05:00
discourse_id_controller_spec.rb
do_not_disturb_controller_spec.rb
drafts_controller_spec.rb FIX: Drafts/reviewables API returned 404 when acting on own resource (#39449) 2026-05-26 09:29:20 +02:00
edit_directory_columns_controller_spec.rb
email_controller_spec.rb
embed_controller_spec.rb FIX: Add visibility check to Embed info (#40896) 2026-06-15 10:20:56 -05:00
emojis_controller_spec.rb FEATURE: Locale-specific emoji search aliases (#39089) 2026-04-06 14:08:46 -03:00
exceptions_controller_spec.rb
export_csv_controller_spec.rb FIX: Suspicious login IPs bypass the moderator IP-visibility setting (#40154) 2026-05-22 13:22:32 +08:00
extra_locales_controller_spec.rb
finish_installation_controller_spec.rb
form_templates_controller_spec.rb SECURITY: Scope form template endpoints to accessible categories 2026-05-19 00:26:04 +01:00
forums_controller_spec.rb
gifs_controller_spec.rb FIX: move klipy gifs request to backend (#41540) 2026-07-08 17:18:42 +04:00
groups_controller_spec.rb FIX: Make auto pseudogroups visible to logged on users (#41498) 2026-07-08 09:28:18 +10:00
hashtags_controller_spec.rb
highlightjs_controller_spec.rb
home_page_controller_spec.rb FEATURE: Allow fallback home routes for crawlers for custom homepage sites (#41234) 2026-06-29 09:57:40 -04:00
inline_onebox_controller_spec.rb SECURITY: Check topic visibility in Oneboxer even when categories match 2026-03-31 15:12:45 +01:00
invites_controller_spec.rb FEATURE: Allow inviting new users directly as admins (#41748) 2026-07-16 14:59:24 -07:00
list_controller_spec.rb SECURITY: Harden ListController top period query against SQL injection (#41718) 2026-07-15 12:17:50 +08:00
metadata_controller_spec.rb FEATURE: Accept shared files via the Web Share Target (#41030) 2026-06-18 17:35:09 -03:00
nested_topics_controller_spec.rb FIX: Run nested replies stats job on all topics when nested is default (#41510) 2026-07-07 14:30:53 -05:00
net_http_header_spec.rb
net_http_timeout_spec.rb
noscript_escape_spec.rb
notifications_controller_spec.rb
offline_controller_spec.rb
omniauth_callbacks_controller_spec.rb FEATURE: Allow HTML for OAuth error message (#41204) 2026-06-26 08:35:06 -05:00
onebox_controller_spec.rb SECURITY: prevent hidden profile data leak via user onebox 2026-03-19 15:21:28 +00:00
permalinks_controller_spec.rb
post_action_users_controller_spec.rb UX: Ignored users reactions/likes should not show up (#39672) 2026-05-11 15:32:29 -03:00
post_actions_controller_spec.rb SECURITY: fix is_warning type coercion bypass in PostActionsController 2026-03-19 15:21:28 +00:00
post_localizations_controller_spec.rb UX: Allow user to set post and topic title language when manually creating post translations in modal (#41734) 2026-07-16 10:43:39 +08:00
post_readers_controller_spec.rb SECURITY: Missing post-level authorization allows whisper metadata disclosure 2026-03-31 15:12:45 +01:00
posts_controller_spec.rb DEV: Add caching for anon requests to /posts (#41775) 2026-07-16 12:22:13 -04:00
presence_controller_spec.rb
published_pages_controller_spec.rb
push_notification_controller_spec.rb
qunit_controller_spec.rb
reviewable_claimed_topics_controller_spec.rb SECURITY: Require topic visibility for category group moderator actions 2026-05-19 00:26:04 +01:00
reviewable_notes_controller_spec.rb
reviewables_controller_spec.rb FEATURE: Allow user to delete their pending topic/post at activity page (#41144) 2026-07-14 09:33:35 +02:00
robots_txt_controller_spec.rb
safe_mode_controller_spec.rb
search_controller_spec.rb SECURITY: Apply category tag visibility to full-text search (#41668) 2026-07-13 15:16:26 -03:00
session_controller_spec.rb UX: Improve password manager and full name handling in code login (#41746) 2026-07-15 10:43:03 -07:00
sidebar_sections_controller_spec.rb
similar_topics_controller_spec.rb
site_controller_spec.rb DEV: Gate read-restricted banner topics (#38496) 2026-03-11 08:14:57 -07:00
sitemap_controller_spec.rb
slugs_controller_spec.rb
static_controller_spec.rb FIX: Localize static topic pages … (#41260) 2026-06-29 21:34:17 +08:00
steps_controller_spec.rb
stylesheets_controller_spec.rb DEV: Allow plugins to register admin-panel-specific CSS (#40345) 2026-05-28 11:03:38 +01:00
svg_sprite_controller_spec.rb
tag_groups_controller_spec.rb FIX: Prevent tag group from saving if private + no group selected (#39599) 2026-04-29 12:10:45 +08:00
tag_localizations_controller_spec.rb FIX: Clean localized tag names (#38488) 2026-03-12 12:54:50 +08:00
tags_controller_spec.rb FEATURE: Prioritize recently used tags in the composer tag picker (#41669) 2026-07-14 13:17:18 +02:00
theme_import_map_spec.rb DEV: Improve cross-plugin/theme import handling (#40939) 2026-06-30 16:11:38 +01:00
theme_javascripts_controller_spec.rb PERF: Move theme settings from js bundle to preload data (#40137) 2026-06-08 16:04:56 +01:00
topic_localizations_controller_spec.rb UX: Allow user to set post and topic title language when manually creating post translations in modal (#41734) 2026-07-16 10:43:39 +08:00
topic_view_stats_controller_spec.rb
topics_controller_spec.rb SECURITY: detailed_404 Security Setting Bypassed (#41549) 2026-07-09 10:58:07 -05:00
uploads_controller_multisite_spec.rb
uploads_controller_spec.rb FIX: Serve inline-safe uploads inline on the local file store (#40739) 2026-07-14 18:52:35 +01:00
user_actions_controller_spec.rb FEATURE: Change default upcoming change promotion status to Beta (#41275) 2026-07-06 09:13:37 +10:00
user_api_key_clients_controller_spec.rb
user_api_keys_controller_spec.rb FIX: Only allow OTPs to be generated from a browser session (#40964) 2026-06-17 18:07:32 +03:00
user_avatars_controller_spec.rb SECURITY: Improve SVG sanitization 2026-06-30 16:10:52 +02:00
user_badges_controller_spec.rb SECURITY: Prevent badge lookup from exposing hidden profiles (#41160) 2026-06-25 13:01:03 +08:00
user_status_controller_spec.rb FIX: Post serialization exposes hidden-profile user status messages (#40885) 2026-06-15 09:25:47 -05:00
users_controller_spec.rb FIX: Validate early for input length in username field on registration (#41525) 2026-07-07 16:27:13 -04:00
users_email_controller_spec.rb DEV: CSRF Token Not Invalidated After Password Reset (#40998) 2026-06-17 16:07:30 -04:00
webhooks_controller_spec.rb SECURITY: Prevent any signed AWS SNS TopicARN from being accepted via webhooks 2026-06-30 16:10:52 +02:00
wizard_controller_spec.rb