slight privacy inconsistency: /api/patches (HTML) lists people to anonymous users but /api/people doesn't

未关闭
#663 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
48/100
Issue 类型
功能
描述清晰度
基本清楚
活跃度
冷清
技术栈
django, python

调研方向

首先比较 /api/patches 和 /api/people 的匿名响应及授权行为,尤其是 Django 过滤表单使用的提交者数据。确定预期的隐私边界,然后为匿名访问添加覆盖测试,并验证远程用户可以按提交者搜索补丁,同时不会暴露超出预期的信息。

由索引模型根据 Issue 内容生成。

描述

The django filtering form's data needed to filter patches by submitter are all supplied in the /api/patches django-REST-framework-HTML document, including submitter names/emails/id-#s, to anonymous not-logged-in users. These are used in the "filter" dialog box. However, /api/person, which would expose the same info, requires authentication. Please consider fixing this inconsistency. Remote anonymous REST API users cannot currently get a list of submitters to search patches of; that would be nice.

主要语言
Python
星标
317
派生
91
PR 合并指标
30 天内没有已合并 PR

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

getpatchwork/patchwork 的其他 Issue

查看 getpatchwork/patchwork 的全部 Issue

相似的 Issue

更多 Python Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。