Cytomine-core icon indicating copy to clipboard operation
Cytomine-core copied to clipboard

Security/privacy issue: Any logged in user can see all other users

Open AustinGil opened this issue 2 years ago • 0 comments

I noticed the user API route (/api/user.json) will return all the registered users as long as I am logged in. Even if I am logged in as just a guest.

I dont know, but this seems like a security or privacy issue. I dont think I want any user to be able to find out all the other users.

AustinGil avatar Jul 14 '21 22:07 AustinGil