Alan Guo Xiang Tan
f31f0b70f8
SECURITY: Hide PM count for tags by default ( #20061 )
...
Currently `Topic#pm_topic_count` is a count of all personal messages tagged for a given tag. As a result, any user with access to PM tags can poll a sensitive tag to determine if a new personal message has been created using that tag even if the user does not have access to the personal message. We classify this as a minor leak in sensitive information.
With this commit, `Topic#pm_topic_count` is hidden from users by default unless the `display_personal_messages_tag_counts` site setting is enabled.
2023-01-31 12:08:23 +08:00
..
2023-01-24 16:32:34 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-24 16:32:34 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-31 10:05:44 +10:00
2023-01-24 16:32:34 +01:00
2023-01-18 11:42:54 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-18 11:42:54 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-24 16:32:34 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-24 16:32:34 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-24 16:32:34 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-24 16:32:34 +01:00
2023-01-18 11:42:54 +01:00
2021-07-27 22:47:59 +08:00
2023-01-09 11:13:29 +00:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2022-12-09 12:01:05 +01:00
2023-01-31 12:08:23 +08:00
2023-01-24 16:32:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-18 11:42:54 +01:00
2023-01-18 11:42:54 +01:00
2023-01-24 16:32:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00
2023-01-24 16:32:34 +01:00