Uploaded image for project: 'MusicBrainz Server'
  1. MusicBrainz Server
  2. MBS-11440

Subscribers page for private collection is not private

    XMLWordPrintable

    Details

      Description

      If a user somehow gets a link to a private collection's subscribers page (https://musicbrainz.org/collection/MBID/subscribers) and is logged in, they can see the collection name, user, entity type and number of entities in the collection (but not the contents of the collection nor any free text fields the user entered).

      Minor because there's no way I can see that a user who can't otherwise see the collection would get the collection MBID, but still.

        Attachments

          Activity

            People

            Assignee:
            reosarevok Nicolás Tamargo
            Reporter:
            reosarevok Nicolás Tamargo
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:

                Packages

                Version Package
                2021-06-14