You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I created an "extern" team on an organization with read-only access to code
only, and assigned a single repository to it. (see the attached screenshot)
When going to /pulls with an account assigned to this extern team (and this
team only) I can list all pull requests, including the title, author, date
number of comments and open/closed status.
When trying to access the details of a single PR I get the expected 404.
Being able to list the pull requests when I specifically disabled the right to
access them is an information leak and a security issue.
Screenshots
The text was updated successfully, but these errors were encountered:
[x]
):Description
I created an "extern" team on an organization with read-only access to code
only, and assigned a single repository to it. (see the attached screenshot)
When going to
/pulls
with an account assigned to this extern team (and thisteam only) I can list all pull requests, including the title, author, date
number of comments and open/closed status.
When trying to access the details of a single PR I get the expected 404.
Being able to list the pull requests when I specifically disabled the right to
access them is an information leak and a security issue.
Screenshots
The text was updated successfully, but these errors were encountered: