Page MenuHomePhabricator

Add a granular capability for user directory browsing
ClosedPublic

Authored by epriestley on Jan 30 2014, 7:40 PM.
Tags
None
Referenced Files
F18460504: D8112.id.diff
Mon, Sep 1, 7:09 PM
F18432186: D8112.diff
Sun, Aug 31, 6:17 AM
F18106907: D8112.diff
Sun, Aug 10, 11:31 PM
F17825888: D8112.id.diff
Jul 26 2025, 6:50 AM
F17817817: D8112.id.diff
Jul 25 2025, 11:53 PM
F17808751: D8112.id.diff
Jul 25 2025, 4:15 PM
F17796707: D8112.id18355.diff
Jul 25 2025, 1:13 AM
F17761045: D8112.diff
Jul 22 2025, 8:22 PM
Subscribers

Details

Summary

Fixes T4358. User request from IRC, but I think this is generally reasonable.

Although we can not prevent users from determining that other user accounts exist in the general case, it does seem reasonable to restrict browsing the user directory to a subset of users.

In our case, I'll probably do this on secure.phabricator.com, since it seems a little odd to let Google index the user directory, for example.

Test Plan

Set the policy to "no one" and tried to browse users.

Diff Detail

Lint
Lint Skipped
Unit
Tests Skipped