Skip to content
This repository was archived by the owner on Sep 24, 2018. It is now read-only.

Don't expose non-public user information in the collection - #1435

Merged
rmccue merged 2 commits into
developfrom
fix-user-visibility
Jul 26, 2015
Merged

rmccue merged 2 commits into
developfrom
fix-user-visibility

Conversation

@rmccue

@rmccue rmccue commented Jul 26, 2015

Copy link
Copy Markdown
Member

Just now in #1397, we added the ability to list users with published posts at /wp/v2/users. Problem is, right now, it's exposing all user data (context=view), but users should only be able to access context=embed

Merging now to avoid security issues, but we can fix up the handling later.

cc @joehoyle

@rmccue rmccue added the Bug label Jul 26, 2015
@rmccue rmccue added this to the 2.0 Beta 4 milestone Jul 26, 2015
@rmccue

rmccue commented Jul 26, 2015

Copy link
Copy Markdown
Member Author

Oh, also, forgot to mention! Major props to @Shelob9 for noticing this one and notifying me immediately. ✨

@rmccue rmccue self-assigned this Jul 26, 2015
rmccue added a commit that referenced this pull request Jul 26, 2015
Don't expose non-public user information in the collection
@rmccue
rmccue merged commit ba64cdb into develop Jul 26, 2015
@rmccue
rmccue deleted the fix-user-visibility branch July 26, 2015 19:54
@joehoyle

Copy link
Copy Markdown
Member

Doh! Apologies for that

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants