Open
Description
Description
Say you are a user named "a", where your profile is set to limited or private. Users not signed in can't see your profile. You decide to rename yourself to "b". Users not signed in visiting the /a profile URL will be visibly redirected to /b (and then shown a 404), which poses a concern since it essentially 'leaks' that this "b" user exists as well as their previous username.
Gitea Version
latest
Can you reproduce the bug on the Gitea demo site?
Yes
Log Gist
N/A
Screenshots
No response
Git Version
No response
Operating System
Linux
How are you running Gitea?
I'm using systemd
, although this isn't process-specific.
Database
SQLite