Skip to content

Possible security issue with user name-contact page #1106

Closed
@AliasQli

Description

@AliasQli

Page https://hackage.haskell.org/user/:username/name-contact can be visited without authorization where :username can be any username, and user's full name and email can be viewed on that page. This seems to be a security issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions