Uploaded image for project: 'MusicBrainz Server'
  1. MusicBrainz Server
  2. MBS-11440

Subscribers page for private collection is not private

XMLWordPrintable

      If a user somehow gets a link to a private collection's subscribers page (https://musicbrainz.org/collection/MBID/subscribers) and is logged in, they can see the collection name, user, entity type and number of entities in the collection (but not the contents of the collection nor any free text fields the user entered).

      Minor because there's no way I can see that a user who can't otherwise see the collection would get the collection MBID, but still.

            reosarevok Nicolás Tamargo
            reosarevok Nicolás Tamargo
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved:

                Version Package
                2021-06-14