slight privacy inconsistency: /api/patches (HTML) lists people to anonymous users but /api/people doesn't

Open
#663 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
48/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Quiet
Tech stack
django, python

Research direction

Start by comparing the anonymous responses and authorization behavior of /api/patches and /api/people, especially the submitter data used by the Django filtering form. Determine the intended privacy boundary, then add coverage for anonymous access and verify that remote users can search patches by submitter without exposing more information than intended.

Written by the indexing model from the issue text.

Description

The django filtering form's data needed to filter patches by submitter are all supplied in the /api/patches django-REST-framework-HTML document, including submitter names/emails/id-#s, to anonymous not-logged-in users. These are used in the "filter" dialog box. However, /api/person, which would expose the same info, requires authentication. Please consider fixing this inconsistency. Remote anonymous REST API users cannot currently get a list of submitters to search patches of; that would be nice.

Dominant language
Python
Stars
317
Forks
91
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from getpatchwork/patchwork

All issues in getpatchwork/patchwork

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.