slight privacy inconsistency: /api/patches (HTML) lists people to anonymous users but /api/people doesn't
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 48/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 冷清
- 领域
- api, authentication, backend
调研方向
首先比较 /api/patches 和 /api/people 的匿名响应及授权行为,尤其是 Django 过滤表单使用的提交者数据。确定预期的隐私边界,然后为匿名访问添加覆盖测试,并验证远程用户可以按提交者搜索补丁,同时不会暴露超出预期的信息。
由索引模型根据 Issue 内容生成。
描述
The django filtering form's data needed to filter patches by submitter are all supplied in the /api/patches django-REST-framework-HTML document, including submitter names/emails/id-#s, to anonymous not-logged-in users. These are used in the "filter" dialog box. However, /api/person, which would expose the same info, requires authentication. Please consider fixing this inconsistency. Remote anonymous REST API users cannot currently get a list of submitters to search patches of; that would be nice.
- 主要语言
- Python
- 星标
- 317
- 派生
- 91
- PR 合并指标
- 30 天内没有已合并 PR
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
getpatchwork/patchwork 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 68/100
getpatchwork/patchwork#668 ·
-
bug web-ui
难度 2/5 1-3 小时 新手友好度 74/100
getpatchwork/patchwork#546 · 2 条评论 ·
-
难度 3/5 1-2 天 新手友好度 52/100
getpatchwork/patchwork#664 ·
-
难度 3/5 1-2 天 新手友好度 45/100
getpatchwork/patchwork#645 ·
-
难度 5/5 一周以上 新手友好度 35/100
getpatchwork/patchwork#636 · 2 条评论 ·
查看 getpatchwork/patchwork 的全部 Issue
相似的 Issue
-
bug
难度 2/5 1-3 小时 新手友好度 82/100
-
难度 2/5 1-3 小时 新手友好度 88/100
use-agent-os/agent-os#3314 ·
-
难度 2/5 1-3 小时 新手友好度 75/100
BasedHardware/omi#15662 · 1 条评论 ·
-
documentation help wanted
难度 2/5 1-3 小时 新手友好度 90/100
-
难度 2/5 1-3 小时 新手友好度 62/100
AiursoftWeb/AnduinOS-2#19 ·