Page MenuHomePhabricator

Add a granular capability for user directory browsing
ClosedPublic

Authored by epriestley on Jan 30 2014, 7:40 PM.
Tags
None
Referenced Files
Unknown Object (File)
Fri, Jun 10, 6:18 AM
Unknown Object (File)
Sun, Jun 5, 8:26 AM
Unknown Object (File)
Fri, Jun 3, 6:14 PM
Unknown Object (File)
May 27 2022, 3:20 AM
Unknown Object (File)
May 24 2022, 10:44 PM
Unknown Object (File)
Apr 8 2017, 4:12 AM
Unknown Object (File)
Nov 25 2016, 12:33 PM
Unknown Object (File)
Oct 25 2016, 3:35 PM
Subscribers

Details

Summary

Fixes T4358. User request from IRC, but I think this is generally reasonable.

Although we can not prevent users from determining that other user accounts exist in the general case, it does seem reasonable to restrict browsing the user directory to a subset of users.

In our case, I'll probably do this on secure.phabricator.com, since it seems a little odd to let Google index the user directory, for example.

Test Plan

Set the policy to "no one" and tried to browse users.

Diff Detail

Lint
Lint Skipped
Unit
Tests Skipped