Skip to content

Previously edited private user URLs will redirect instead of 404'ing #34169

Open
@VillainsRule

Description

@VillainsRule

Description

Say you are a user named "a", where your profile is set to limited or private. Users not signed in can't see your profile. You decide to rename yourself to "b". Users not signed in visiting the /a profile URL will be visibly redirected to /b (and then shown a 404), which poses a concern since it essentially 'leaks' that this "b" user exists as well as their previous username.

Gitea Version

latest

Can you reproduce the bug on the Gitea demo site?

Yes

Log Gist

N/A

Screenshots

No response

Git Version

No response

Operating System

Linux

How are you running Gitea?

I'm using systemd, although this isn't process-specific.

Database

SQLite

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions