Page MenuHomePhabricator

Add a granular capability for user directory browsing
ClosedPublic

Authored by epriestley on Jan 30 2014, 7:40 PM.
Tags
None
Referenced Files
F18820199: D8112.id.diff
Wed, Oct 22, 1:14 PM
F18757781: D8112.id.diff
Sun, Oct 5, 7:26 PM
F18750078: D8112.diff
Sat, Oct 4, 6:23 AM
F18734583: D8112.id.diff
Tue, Sep 30, 10:57 PM
F18633955: D8112.diff
Sep 16 2025, 9:14 PM
F18625991: D8112.id18344.diff
Sep 16 2025, 12:06 AM
F18624817: D8112.diff
Sep 15 2025, 9:07 PM
F18460504: D8112.id.diff
Sep 1 2025, 7:09 PM
Subscribers

Details

Summary

Fixes T4358. User request from IRC, but I think this is generally reasonable.

Although we can not prevent users from determining that other user accounts exist in the general case, it does seem reasonable to restrict browsing the user directory to a subset of users.

In our case, I'll probably do this on secure.phabricator.com, since it seems a little odd to let Google index the user directory, for example.

Test Plan

Set the policy to "no one" and tried to browse users.

Diff Detail

Lint
Lint Skipped
Unit
Tests Skipped